hns-workflow-ci-loop

Warn

Audited by Snyk on Aug 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Source: GitHub PR checks/failure logs are ingested at runtime via the required watch/poll loop gh pr checks <PR> ... and the handoff includes failedChecks[].logUrl for later log fetching, where the outsider-authored content originates from the PR’s commit diffs and CI log text (externally submitted via PR creation/changes).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 04:42 AM
Issues
1
Security Audit — snyk — hns-workflow-ci-loop