sinch-conversation-api
Warn
Audited by Snyk on Jun 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Outsider free text can enter the LLM context via runtime inbound webhook payloads (e.g.,
MESSAGE_INBOUND/MESSAGE_INBOUND_SMART_CONVERSATION_REDACTION/SMART_CONVERSATION), where user-authored message text and related fields are attacker-controlled and may be forwarded into the agent’s prompt.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata