github-operation
Warn
Audited by Snyk on Aug 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md’s GitHub Operation describes reading issue/PR bodies, comments, review text, and CI logs via the in-session GitHub tool channel (
mcp__github__*from the connected GitHub MCP server), and those texts are explicitly treated as attacker-influenceable free text that an outsider can post to GitHub (e.g., comments/bodies/reviews), meaning runtime ingestion is not gated to trusted first-party authored content.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata