vp-deps-upgrade
Warn
Audited by Snyk on May 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly ingests external, untrusted content — e.g., querying GitHub PRs/releases with
gh pr view/gh api repos/{owner}/{repo}/releases, parsing PR titles/bodies (deps-bot-handling.md), and using Context7query-docsand public changelogs — and then interprets that content to decide migration steps and run tools, so third-party text can materially influence actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata