paseo-loop
Warn
Audited by Snyk on May 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md workflow and examples (e.g., "Check PR #42. Review CI, comments, and branch status." and the use of
--verify-check "gh pr checks 42"plus verifier prompts to inspect changed files/tests) require the agent to read and act on user-generated third-party content (PRs, comments, CI outputs), which could carry indirect prompt injections.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata