ci-watchdog
Warn
Audited by Snyk on May 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches and parses CI/PR data and logs from GitHub (e.g., "gh run view --log-failed" and "gh pr checks --json | python3 parse_failures.py" in SKILL.md and scripts/parse_failures.py), and it reads and acts on that user-generated third-party content to diagnose and apply fixes, which could allow indirect prompt injection.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata