issue-to-implementation

Warn

Audited by Snyk on Feb 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). This skill fetches and ingests arbitrary, user-generated GitHub issue bodies and comments (see SKILL.md Phase 1 and scripts/fetch_issue.sh which call gh issue view ... --comments), and those untrusted third‑party contents are explicitly read and used to drive analysis, implementation plans, and code/PR actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 28, 2026, 12:40 PM