serving-the-api

Warn

Audited by Snyk on Aug 22, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The “serving-the-api” workflow exposes an HTTP REST server with endpoints like POST /v1/scrape, POST /v1/crawl, and POST /v1/map that ingest user-supplied request bodies (e.g., url, search) and then perform crawling/scraping of those URLs at runtime, creating an indirect prompt-injection surface from outsider-authored page content.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 22, 2026, 10:23 PM
Issues
1
Security Audit — snyk — serving-the-api