pr-automate
Warn
Audited by Snyk on May 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill explicitly polls GitHub PR data (e.g., "Poll for new reviews or comments" and uses
gh api/gh pr checks) and relays the full content of reviews/comments (user-generated, potentially untrusted) back to the main thread, so third-party comments can influence agent behavior and prioritization.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata