issue-work-loop
Warn
Audited by Snyk on Jul 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.78). Yes: in the required runtime workflow, the skill queries GitHub issue/PR title/body and sends reviewer/implementer/fixer prompts that include those untrusted texts (e.g., PR title/body and any linked issue context) into the worker LLM context via
herdr-agent-commsusing the role prompts.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata