task-completition-evaluation
Warn
Audited by Snyk on Jun 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The skill’s runtime workflow ingests user-provided collaboration evidence (e.g., Slack thread URLs and GitHub issue/PR/discussion URLs) and then runs
scripts/eval_slack_e2e.py/scripts/eval_github_e2e.py, which will fetch and include outsider-authored conversation text (messages/comments) from those threads into the agent/LLM context for evaluation.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata