pr-creator

Warn

Audited by Snyk on May 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The SKILL.md workflow explicitly tells the agent to fetch and analyze remote git/GitHub data (e.g., "git fetch origin --prune", "git diff origin/main...feature-branch", and to use commit/branch data and GitHub commit/PR URLs), which means it ingests untrusted, user-generated repository content from third-party remotes that can directly influence PR-generation and subsequent actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 20, 2026, 12:24 PM
Issues
1
Security Audit — snyk — pr-creator