github
Warn
Audited by Snyk on Mar 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's SKILL.md and scripts show multiple tools (e.g., get_file_contents, pull_request_read including get_diff/get_files/get_review_comments, list_issues, search_code, etc.) that fetch public GitHub repository files, PR diffs, issues and comments via the OneKey Agent Router — untrusted, user-generated content the agent is expected to read and which can directly influence follow-up actions like commenting, merging, or updating files.
Audit Metadata