github-gist

Warn

Audited by Snyk on Feb 27, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's required workflows and reference files (SKILL.md, references/search-and-manage.md, and references/workflows.md) instruct the agent to list, view, clone, and even raw-pipe GitHub gists (public user-generated content) — i.e., fetching and executing arbitrary third-party gist content — which could inject instructions that change subsequent actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 27, 2026, 03:29 PM