github-actions-finops
Warn
Audited by Snyk on Jun 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required runtime path is the deterministic script
scripts/github-actions-finops.sh, which in live mode ingests GitHub API JSON for workflow runs (gh api /repos/{owner}/{repo}/actions/runs) and optional billing (/orgs/{org}/settings/billing/actions); the workflow-run fields are outsider-authored data from other users/bots and are parsed into LLM-visible text via the script’s printedSTATUS/ISSUESand counts.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata