github

Warn

Audited by Snyk on Jul 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). Outsider free text can enter the LLM context when the agent uses Apideck Issue Tracking endpoints (e.g., listing/reading GitHub issues and comments) because those responses include body text authored by GitHub users other than the operating user, which the agent then passes into the LLM; the SKILL.md also describes an escape-hatch Proxy that can fetch arbitrary GitHub endpoints returning outsider-authored prose.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 1, 2026, 11:02 AM
Issues
1
Security Audit — snyk — github