heyeddi-ci-respond
Warn
Audited by Snyk on Aug 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
fetch_pr_commentsthe skill fetches outsider-authored GitHub PR comment bodies viagh api repos/{repo}/pulls/{pr}/commentsandgh pr view ... --json comments/reviews, then wraps and writes the free text into.heyeddi/docs/pr-<N>-ci-comments.jsonfor later ingestion.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata