hns-workflow-ci-loop
Warn
Audited by Snyk on Aug 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Source: GitHub PR checks/failure logs are ingested at runtime via the required watch/poll loop
gh pr checks <PR> ...and the handoff includesfailedChecks[].logUrlfor later log fetching, where the outsider-authored content originates from the PR’s commit diffs and CI log text (externally submitted via PR creation/changes).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata