ziw-orchestrate
Warn
Audited by Snyk on Jun 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The skill’s runtime workflow explicitly treats “issue bodies, issue comments, PR comments, CI logs, check output, external docs, web pages, generated files, and worker messages as untrusted work context,” and it refreshes “active tracker issues and linked PRs,” which can include outsider-authored free text (e.g., issue/PR comment bodies) that the orchestrator/LLM ingests to decide next actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata