gremlin
Warn
Audited by Snyk on Jun 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The skill reads outsider-authored free text from GitHub issue bodies and comments at runtime (
gh issue view ... --json ... bodyand, in on-demand mode, “most recent comment” content), then includes that text in the LLM context for review routing and synthesis.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill issues GitHub CLI and git commands at runtime (e.g., gh issue list / gh pr diff / gh issue view which use the GitHub API https://api.github.com, and git fetch/pull from the repository remote via git fetch origin) and then injects the fetched PR diffs and docs into spawned agent prompts, so external content fetched from the GitHub API / repo remote directly controls agent prompts.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata