convex-expo-push-notifications

Warn

Audited by Snyk on Mar 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill explicitly ingests push notification payloads from external senders and then reads/acts on notification.request.content.data to perform deep-linking/behavior (see the response listener in references/client-hook.md and App layout code in app/_layout.ts), and the docs even show sending notifications via exp.host / expo.dev — so untrusted third-party notification content can materially influence app actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 15, 2026, 10:47 PM
Issues
1