github-agile
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). This skill's runtime scripts (notably scripts/gh-audit.ts and scripts/gh-sync-context.ts) call the GitHub CLI / API (e.g.,
gh issue list,gh pr list,gh api ...) and ingest issue/PR titles and bodies from GitHub — i.e., untrusted, user-generated third‑party content that the agent reads and interprets.
Audit Metadata