gsdl-close-loop

Warn

Audited by Snyk on Aug 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Step 1 gathers Step 8 PR data via gh pr view [PR_URL] --json ... (PR title/body-derived fields, reviews/comments) and Step 6 later incorporates Step 7’s evidence into tracker comments, so outsider-authored free text in GitHub PR reviews/comments can be ingested at runtime through the required PR_URL fetch.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 11, 2026, 08:13 AM
Issues
1
Security Audit — snyk — gsdl-close-loop