github

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's SKILL.md and scripts show multiple tools (e.g., get_file_contents, pull_request_read including get_diff/get_files/get_review_comments, list_issues, search_code, etc.) that fetch public GitHub repository files, PR diffs, issues and comments via the OneKey Agent Router — untrusted, user-generated content the agent is expected to read and which can directly influence follow-up actions like commenting, merging, or updating files.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 08:45 AM
Security Audit — snyk — github