sync-modules
Warn
Audited by Snyk on Jun 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The skill reads user-provided
$ARGUMENTSto locate a feature spec, then fetches and ingests GitHub issue/sub-issue content at runtime (“View the feature issue and its sub-issues on the GitHub”), which is outsider-authored free text that can be included in the agent’s LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata