land-pr
Warn
Audited by Snyk on Jun 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.78). The workflow repeatedly ingests outsider-authored free text from GitHub at runtime—e.g.,
gh issue view <ISSUE> --json ... body,url,labels,comments(issue body/comments) andgh pr view <PR> --json ... closingIssuesReferences(PR-provided references)—which can contain arbitrary text that the agent may include in its LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata