project-session-manager

Warn

Audited by Snyk on Mar 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). Yes — the SKILL.md workflow and scripts explicitly fetch PR/issue data (e.g., "Fetch PR info" via gh pr view, provider_fetch functions), clone repositories (git clone of third‑party repos / provider clone_url), create worktrees and then launch Claude Code inside that worktree (tmux send-keys "claude"), so untrusted PR bodies, issue descriptions, and repository files from public third‑party sources are presented to the agent and can materially influence its actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 24, 2026, 07:43 AM
Issues
1
Security Audit — snyk — project-session-manager