review-changes
Warn
Audited by Snyk on Feb 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's mandatory Phase 2.5 requires locating and reading original requirements from third-party, user-generated sources such as "GitHub issue (
gh issue view <number>) / PR description", which the agent must interpret to decide coverage and next actions, creating a clear vector for indirect prompt injection.
Audit Metadata