pipeline
Fail
Audited by Snyk on May 15, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 0.90). The prompt contains an explicit instruction to always spawn agents with mode: "bypassPermissions" to override normal permission prompts (and note the Agent tool default "acceptEdits" is to be overridden), which is a hidden/deceptive permission-bypassing behavior outside the plain purpose of invoking pipelines.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The pipeline explicitly runs gh issue list / gh api calls (see workflows/auto-dev.yaml pre-triage and scope-selection) and parses issue bodies/labels (user-generated GitHub issues) to decide scope, dependencies, and next steps, so untrusted third-party content is ingested and can materially influence subsequent tool invocations.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The prompt explicitly instructs spawned agents to use mode:"bypassPermissions" (i.e. bypass security/permission prompts) and delegates file writes to subagents, which encourages bypassing security controls and enables state-changing actions on the host.
Issues (3)
E004
CRITICALPrompt injection detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata