workflow-integration-gitlab
Warn
Audited by Snyk on Jul 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Yes: the required FIND workflow (
gitlab_pr.py→gitlab_ops.py→fetch_pr_comments_data) fetches outsider-authored MR discussion note bodies from GitLab and then stores them as readable prose in the ledger underraw_input.{body}(untrusted comment text), which is later promoted and read by the LLM consumer.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata