stet
Warn
Audited by Snyk on May 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches and parses open/public repository content and PRs (e.g., "discover (fetch PRs -> prefilter -> LLM scoring -> manifest)" and commands like "stet suite discover --repo owner/repo" and the "CI Miner"/"Docs Reader" steps that read CI, README, and PRs) and uses those untrusted, user-generated artifacts to synthesize test commands, Dockerfiles, task manifests and to drive evals, so third‑party content is ingested and can materially influence agent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata