and-finish
Warn
Audited by Snyk on Jul 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The workflow explicitly reads a “complete delivery unit” and “review and verification evidence” from the configured backend and GitHub pull requests (i.e., outsider-authored PR/issues/discussion content via GitHub), which can be free-text and may be used to build the LLM’s context when resolving/validating the PR head and evidence.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata