git-platform
Warn
Audited by Snyk on May 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's SessionStart hooks (notably the referenced fetch-recent-discussions.sh and the "List Recent Discussions by Category" GraphQL query in modules/command-mapping.md) explicitly fetch GitHub discussion bodies/titles (user-generated, public content) and inject them into session context, so that third-party content is read and can influence subsequent tool use and actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata