jj
Warn
Audited by Snyk on Mar 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's workflow explicitly runs remote git operations (e.g., "jj git clone ", "jj git fetch", and subsequent "jj log"/"jj diff" inspection) which ingest and have the agent read/interprete arbitrary public repository content (user-generated) that can influence decisions like rebases, pushes, conflict resolution, and PR creation.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata