cicd
Warn
Audited by Snyk on May 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The SKILL.md explicitly instructs fetching and reading user-generated GitHub content (see "Locating the PR from a CI Branch" and "Reading CI Job Logs" which use
gh pr view,gh pr diff,gh run viewandgh run downloadto retrieve PR metadata, diffs, and CI artifact logs), so the agent would ingest untrusted third‑party content that can influence investigations and next actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata