git-master
Warn
Audited by Snyk on May 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill explicitly reads and interprets repository history and remote commits (e.g., "git log -30 --pretty=format:'%s'", "git fetch origin", "git log -S ... --all") and mandates using those commit messages/diffs to detect style and drive commit/rebase decisions, so untrusted/user-generated commit content from remotes could indirectly inject instructions that change agent behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata