backport-management
Warn
Audited by Snyk on Mar 31, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly ingests user-generated third-party content — e.g., exporting Slack channel messages via "slackdump export" from #frontend-releases and fetching GitHub PR details with "gh pr view" — and then interprets those messages/PR metadata to decide and drive backporting actions, so untrusted content can influence tool use.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata