qa
Warn
Audited by Snyk on Jul 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). SKILL.md requires the agent to “Let the user describe the problem in their own words” and then use that user-provided free text to create GitHub issues, which implies the agent’s LLM context will include outsider-authored user messages at runtime (the user is not the operating user’s own authored prompt).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata