gh
Warn
Audited by Snyk on Jul 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required workflow is to run
ghcommands that fetch GitHub data (e.g., PR/issue/workflow/run details and logs) and pass the resulting JSON/text into the agent’s context via--json/--jq/--logoutputs, which can include outsider-authored free text like PR titles/bodies, issue comments, and workflow logs.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata