shipping-pr
Warn
Audited by Snyk on May 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). This skill explicitly reads user-generated GitHub content (PR reviews and comments via
gh pr list/gh pr viewand commit statuses/check-runs viagh apiin SKILL.md and reference/*.md) and uses those reviews/statuses to decide waits, dispatch the resolving-pr-blockers agent, and drive commits/pushes, so untrusted third-party content can materially influence agent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata