backstage-patterns
Warn
Audited by Snyk on Apr 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The SKILL.md explicitly configures Backstage to auto-discover catalog-info.yaml across a GitHub org (app-config.yaml providers.github myorg with repository: '.*') and includes Scaffolder/GitHub integration steps that fetch/register repo contents from github.com, so arbitrary public GitHub (user-generated) content is fetched and interpreted as part of normal workflows and can influence actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata