ci-analyze

Fail

Audited by Snyk on Jun 17, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (medium risk: 0.50). 虽然大部分内容是明确、与 CI 分析相关且包含安全边界,但最后一句“与本 skill 冲突时以本 skill 为准”要求在与 AGENTS.md(系统规范)冲突时优先执行该 skill,构成了显式的试图覆盖/替换系统级指令的行为,属于应当标记的注入式指令。

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.65). 该 skill 在运行时会通过 gh pr checks / gh run view --log-failed 获取 GitHub Actions 的失败日志与相关文本;这些日志/输出属于 GitHub 运行环境与(可能包含)外部贡献者触发的内容,属于“公共/第三方运行日志文本在运行时被读取为可读 prose 并进入 LLM 上下文”的路径。

Issues (2)

E004
CRITICAL

Prompt injection detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 17, 2026, 09:06 AM
Issues
2