github-initiative-pulse

Warn

Audited by Snyk on May 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's workflow (SKILL.md and modules/status-digest.md) explicitly requires syncing/pulling tracker JSON from GitHub Projects and using GitHub search queries to read issues/PRs (user-generated third-party content) which directly influences status generation and follow-up actions, so untrusted content could alter agent behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 17, 2026, 06:22 AM
Issues
1
Security Audit — snyk — github-initiative-pulse