git-platform

Warn

Audited by Snyk on May 9, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill's SessionStart hooks (notably the referenced fetch-recent-discussions.sh and the "List Recent Discussions by Category" GraphQL query in modules/command-mapping.md) explicitly fetch GitHub discussion bodies/titles (user-generated, public content) and inject them into session context, so that third-party content is read and can influence subsequent tool use and actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 9, 2026, 07:37 AM
Issues
1