zynna-auth
Warn
Audited by Snyk on Apr 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The scripts/auth.js workflow fetches JSON from an API and verification URLs (DEFAULT_API_BASE or env-overridden ZYNNA_AUTH_API_BASE / ZYNNA_AUTH_WEB_BASE and derived token endpoints) and directly parses payload.status/plan/credentials to drive control flow (approve/deny/save credentials/open browser), so untrusted third-party responses can materially influence actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata