gh-treasure-hunt
Warn
Audited by Snyk on Jun 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The workflow pulls and then ingests outsider-authored free text from GitHub PR/issue bodies/comments via
gh pr view/gh pr checks/gh issue list(and related fields), which are untrusted outsider content that can be included in the agent’s LLM context during “confirm each shortlisted PR from code, tests, comments, and checks.”
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata