smooth-rebase

Warn

Audited by Snyk on Jul 6, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). At runtime the skill runs git fetch origin and then git rebase origin/<default-branch>, which ingests commit contents (including any outsider-authored changes from the remote repository’s default branch) into the local working tree/LLM context via conflict markers and git show :1/:2/:3 outputs.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 6, 2026, 12:38 PM
Issues
1
Security Audit — snyk — smooth-rebase