wk-commit

Warn

Audited by Snyk on Aug 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). In wk-commit Post-Push: PR Sync, the runtime reads first-party service-generated PR title/body via gh pr view and then compares/edits it (gh pr edit), but this requires the PR content to be from the user’s repo/PR authors rather than an outsider being able to inject arbitrary free text into a queue/feed the workflow monitors without selecting an item.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 04:30 AM
Issues
1
Security Audit — snyk — wk-commit