project-weekly-report
Warn
Audited by Snyk on Aug 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The runtime workflow reads and forwards Git commit metadata/body and file paths from the target repository into the LLM for Chinese summarization (SKILL.md “Read the collector's JSON” → scripts/collect_git_work.py emits commit subjects/bodies into
project-weekly-report.git-work.v1).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata