app-store-server-notifications-android
Warn
Audited by Snyk on Aug 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). RTDN events are delivered to the service via a Google Cloud Pub/Sub topic and the skill’s workflow ingests JSON from Pub/Sub push/pull messages (JWT-signed event payloads), meaning outsiders who can publish to the topic/feed could supply free text that the agent runtime processes without selecting a specific trusted item first.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata