github-commit-pr
Warn
Audited by Snyk on Aug 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The workflow reads GitHub Actions failure logs at runtime via the
gh run watch/error-handling path inreferences/ci-and-merge.md, and those logs can include outsider-authored free text (e.g., from failing code/test output or untrusted PR content) that the LLM would ingest (especially when delegating log root-cause to a subagent).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata