sinch-voice-api
Warn
Audited by Snyk on Jun 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required runtime workflow for this skill is handling Sinch Voice callback events (ICE/ACE/PIE) where the agent must read outsider-authored JSON fields like
menuResult.value/clifrom the inbound POST body and use them to generate SVAML responses, which then become LLM context (indirect prompt injection risk via untrusted callback payload text).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata