pr-evidence
Warn
Audited by Snyk on Jul 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Outsider-authored free text (the PR body content and “every public URL” the workflow reads to re-verify) is ingested at runtime via the required step to “Read the intent, diff, current body…” and “Re-read… and every public URL,” creating an indirect prompt-injection risk from GitHub PR author text and fetched public pages/links.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata