drift-analysis
Warn
Audited by Snyk on Jul 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In SKILL.md, the runtime workflow’s collectors.js “GitHub Data” step reads open issues/PRs (including their titles/content used for “Theme analysis from titles”) and then passes the collected data into the plan-synthesizer Sonnet call, so outsider-authored text from GitHub issue/PR authors is ingested without requiring prior selection by a specific item.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata