github-supply-chain-hardening-analysis
Warn
Audited by Snyk on Jul 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). High likelihood:
scripts/gh_orchestrator.pyclones outsider-owned GitHub repositories at runtime and reads free-text contents of workflow/docs/README/Dockerfile files (e.g.,.github/workflows/*.yml,README.md, etc.) intotext, then incorporates those derived snippets and rationales into the generated proposal JSON that is returned via stdout/used for the agent’s final response.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata