ai-repo-setup

Warn

Audited by Snyk on Jun 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.65). The skill’s workflow can ingest outsider-authored free text when it integrates with an external issue tracker: it queries tracker items and uses their descriptions/status (publicly authored by others) as LLM context during “query the tracker for current status” and “create issues… write back the ID,” which can include arbitrary issue body text from non-operating users.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 21, 2026, 06:57 PM
Issues
1
Security Audit — snyk — ai-repo-setup