jj-vcs
Warn
Audited by Snyk on May 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The SKILL.md explicitly references fetching and interacting with arbitrary Git remotes (e.g., "Quick Start: jj git clone", references/git.md with "clone" and "fetch") and commands that display repo contents (e.g., references/show.md, references/file.md), so the skill would consume untrusted, user-generated third‑party repository content that could influence agent actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata