reference-repos

Warn

Audited by Snyk on Aug 9, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). The skill’s runtime workflow clones and updates fixed reference repositories via a tracked shell script (git clone/pull --ff-only) using canonical clone URLs and then materializes the downloaded repository contents under .repos/, so outsider-authored text (from those repos, if hosted by others) is ingested by the LLM only when the agent later reads that local code/files.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 9, 2026, 10:48 AM
Issues
1
Security Audit — snyk — reference-repos