pull-request

Warn

Audited by Snyk on Aug 30, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The required workflow instructs the agent to view and process GitHub pull requests, issues, and review comments using gh pr view and gh issue view, which exposes the agent to outsider-authored free text from untrusted PR comments and contributions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 30, 2026, 05:09 PM
Issues
1
Security Audit — snyk — pull-request