sinch-voice-api

Warn

Audited by Snyk on Jun 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). The required runtime workflow for this skill is handling Sinch Voice callback events (ICE/ACE/PIE) where the agent must read outsider-authored JSON fields like menuResult.value / cli from the inbound POST body and use them to generate SVAML responses, which then become LLM context (indirect prompt injection risk via untrusted callback payload text).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 15, 2026, 10:16 AM
Issues
1
Security Audit — snyk — sinch-voice-api