release-process
Warn
Audited by Snyk on Jun 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The workflow runs
tools/changelog.pywhich (via the GitHub token) reads PR/issue text from GitHub (outsider-authored PR titles/body/comments) to generateCHANGELOG.md, and that generated free text is then ingested by the agent/LLM when the script output/notes are used for release creation.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata