om-stabilize-ci

Warn

Audited by Snyk on Jul 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). SKILL.md requires reading CI logs and PR/check metadata from the repository/tracker at runtime (e.g., “get-run-failed-logs”, “get-pr-checks”, “get-required-checks”, “comment-pr”); those are outsider-authored free text (CI log output and PR titles/bodies/comments from other actors) that can be ingested into the agent’s LLM context for diagnosis and reporting.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 12, 2026, 01:47 PM
Issues
1
Security Audit — snyk — om-stabilize-ci