sred-work-summary

Warn

Audited by Snyk on Aug 9, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In Step 4/6 the workflow “Find all the Github PRs … in the time window” and later uses “both the title of the PR and the description of the PR for grouping,” meaning outsider-authored PR title/description text is ingested from GitHub at runtime.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 9, 2026, 11:30 PM
Issues
1
Security Audit — snyk — sred-work-summary