cross-repo-discovery
Warn
Audited by Snyk on Jul 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). This skill’s required workflow reads Azure DevOps project/repo description body text from
az devops project show/az devops invoke ... projectsandaz devops repos list, then writes those strings intoALL_REPOS.mdand uses them to decide what to present/answer about; since those descriptions are authored by outsiders (other users in the org) and can contain free text, they can flow into the agent/LLM context when the agent readsALL_REPOS.mdor otherwise incorporates the generated markdown.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata