gremlin

Warn

Audited by Snyk on Jun 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). The skill reads outsider-authored free text from GitHub issue bodies and comments at runtime (gh issue view ... --json ... body and, in on-demand mode, “most recent comment” content), then includes that text in the LLM context for review routing and synthesis.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill issues GitHub CLI and git commands at runtime (e.g., gh issue list / gh pr diff / gh issue view which use the GitHub API https://api.github.com, and git fetch/pull from the repository remote via git fetch origin) and then injects the fetched PR diffs and docs into spawned agent prompts, so external content fetched from the GitHub API / repo remote directly controls agent prompts.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 29, 2026, 02:02 PM
Issues
2