review-with-untracked
Warn
Audited by Snyk on Jun 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Outsider free text can enter the LLM context via the runtime-dispatched callees (
Skill(<callee>)in step (d)), which rungit diff <Base ref>/git status ...and then read and include the resulting diff/frontmatter content (authored by other parties) in their own LLM prompts; this skill itself also reads file contents in step (f) to parse YAML frontmatter, which can be outsider-authored text.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata