rhdh-overlay
Warn
Audited by Snyk on Aug 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
workflows/triage-prs.mdandscripts/triage-prs.py, the runtime reads outsider-authored free text from GitHub PRs by listing open PRs and ingesting theirtitle,labels, and other PR metadata (includingpr.get("title", "")which is used in output and parsing) from the overlay repository without first selecting a specific trusted item.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata