glab-securefile
Warn
Audited by Snyk on Jul 31, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In the required runtime workflow for
glab securefile download/get/list/remove/update, the agent reads secure-file metadata and (optionally) file contents from a target GitLab project based on user-supplied selectors (e.g.,--all,--id,--name,--repo), which can be outsider-authored content if the target project is attacker-controlled.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata