specrail-pr-gate
Warn
Audited by Snyk on Jul 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The workflow only ingests
<evidence.json>produced by the local script (checks/github_pr_evidence.py) and then runschecks/pr_gate.py; that evidence is derived from GitHub PR/issue content authored by outsiders, so it can include outsider-provided free text that is then fed into the LLM context by the gate script at runtime (indirect prompt injection risk).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata