gh
Warn
Audited by Snyk on Aug 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In SKILL.md’s described required workflow for the GitHub CLI, the agent can be made to read issue/PR/discussion content (including comment bodies and discussion bodies) from GitHub at runtime via commands like
gh discussion view/listwith--commentsandgh api .../pulls/{n}/comments, where outsider-authored text from users is ingested through the selected item.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata