github-agile

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). This skill's runtime scripts (notably scripts/gh-audit.ts and scripts/gh-sync-context.ts) call the GitHub CLI / API (e.g., gh issue list, gh pr list, gh api ...) and ingest issue/PR titles and bodies from GitHub — i.e., untrusted, user-generated third‑party content that the agent reads and interprets.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 08:39 PM