crabpot-perf-metrics
Warn
Audited by Snyk on Jul 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The workflow ingests outsider-authored free text via GitHub by reading report artifacts (e.g.,
reports/crabpot-*.json) from target repos/branches specified by the user, using GitHub API calls such as the contents endpoint that will return the file text/JSON for the LLM to interpret.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata