neon-functions
Warn
Audited by Snyk on Jun 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The runtime path ingests outsider-authored free text via the public client request body/parameters (e.g., MCP
POST /mcpcalls or agent chatPOSTmessages) into the function’s LLM/tooling context, which is then forwarded to the model—this is indirect prompt injection risk from arbitrary caller input.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata