organizing-with-labels
Warn
Audited by Snyk on Mar 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's runtime workflows and scripts explicitly fetch and interpret user-generated GitHub issue content (e.g., scripts/label-operations.py's infer_labels calls 'gh issue view' and SKILL.md Pattern 2 describes "analyze issue content for keywords" and then bulk-apply labels), so untrusted third-party text from issues can directly influence automated actions.
Audit Metadata