vtex-io-http-routes
Warn
Audited by Snyk on Apr 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill defines HTTP routes and webhook/callback endpoints that directly read and act on untrusted external HTTP request content (e.g., ctx.request.body, route params, and headers in examples like createReview and rawGetOrder under node/routes), so third‑party requests could materially influence downstream actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata