senpi-account-status
Warn
Audited by Snyk on Aug 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Source and runtime path:
scripts/status.pycalls Senpi MCP tools (user_get_me,user_get_senpi_points,get_loyalty_tiers,user_get_referral_rewards) and ingests the returned JSON fields as LLM input/output, and those tool-returned fields can include user-controlled free text (e.g., profile/tier strings) without any required “select specific item” gating.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata