develop-story
Warn
Audited by Snyk on May 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly reads and parses user-generated content from third-party trackers (GitHub issues/pr bodies and comments via
gh issue view/gh pr viewand the tracker-state-poller Explore subagent, e.g. Phase 0a inline resolution and the resume/artifact verification steps) and uses those results to resolve document paths, decide resume actions, verify QA/PR state, and drive next tool invocations, so untrusted external text can materially influence agent behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata