Warn
Audited by Snyk on Aug 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). Runtime path ingests outsider-authored free text only via the
webhook verifyflow, where the raw webhook request body from an inbound HTTP POST is read from--body-fileand verified; however the workflow is gated by ECDSA signature + timestamp verification before trusting event contents, so only directly supplied webhook text reaches the verifier.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata