email

Warn

Audited by Snyk on Aug 5, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). Runtime path ingests outsider-authored free text only via the webhook verify flow, where the raw webhook request body from an inbound HTTP POST is read from --body-file and verified; however the workflow is gated by ECDSA signature + timestamp verification before trusting event contents, so only directly supplied webhook text reaches the verifier.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 5, 2026, 09:20 PM
Issues
1
Security Audit — snyk — email