github-profile-readme
Warn
Audited by Snyk on Jun 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The required workflow can run
scripts/gather_github.sh <owner>, which usesgh apito fetch the target account’s public profile fields (e.g., bio, website, social URLs) and current README text fromrepos/${OWNER}/${OWNER}/contents/README.mdorrepos/${OWNER}/.github/contents/profile/README.md, and that fetched free-form text is then used as LLM context to generate the new profile README.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata