worktree
Warn
Audited by Snyk on May 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill calls the GitHub CLI (gh pr list --head --state all --json number,state,mergedAt) in both status and cleanup steps to read PR metadata from GitHub (user-generated, third-party content) and uses that PR state to decide whether to remove worktrees/branches, so external PR data can materially influence actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata