gpc-release-flow

Warn

Audited by Snyk on May 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's SKILL.md explicitly reads external, user-generated content — e.g., "Auto-detect from your live Play listing (one API round-trip)" and "Show release history from GitHub" used by gpc changelog generate (including the --ai flow that translates and --apply which writes notes), so the agent ingests untrusted third-party pages/commits and uses that content to drive generation and write actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 18, 2026, 09:08 AM
Issues
1
Security Audit — snyk — gpc-release-flow