actions-automation
Warn
Audited by Snyk on Aug 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). SKILL.md describes GitHub Actions triggers that may process outsider-authored payloads (notably
repository_dispatchviagithub.event.client_payload, andissues/issue_comment/pull_request-related events), but it does not specify any particular required runtime workflow step that ingests free-form attacker text into the LLM.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata