check-pr

Warn

Audited by Snyk on Apr 8, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches and ingests PR/MR details, discussions, comments, and bot notes from third-party GitHub/GitLab APIs (see SKILL.md steps 2, 4.C, 7, 8 and references/gitlab-api.md), and it uses that user-generated content to decide actions (categorize issues, fix code, and resolve threads), so untrusted comment/body text could influence agent behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 8, 2026, 01:40 PM
Issues
1