github-repo-explore
Warn
Audited by Snyk on May 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md explicitly instructs the agent to search, clone, and read public GitHub repositories (see "Phase 3: Search GitHub", "Phase 4: Clone Repository to Cache", and "Phase 5: Explore Repository"), which pulls untrusted, user-generated content from the open web that the agent is expected to interpret and can influence subsequent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata