manage-ci-artifacts
Warn
Audited by Snyk on Jul 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). At runtime, the
persistsubcommand fetches CI job logs (outsider-authored text from GitHub/GitLab) via theplan-marshall:tools-integration-ci:ci fetch-logsabstraction and writes the resulting log content into.logfiles andmanifest.toon, which are then available for later LLM context during retrospectives.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata