repo-audit
Warn
Audited by Snyk on Jul 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Required workflow runs
scripts/collect_evidence.py, which fetches outsider-authored repo content from GitHub (README text viagh api repos/.../readme, community profile, and file presence) and can readREADME.md/other files from the checked-out repo at runtime, then feeds that evidence into the agent’s LLM when it produces the audit report.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata