building-github-index

Warn

Audited by Snyk on Feb 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's scripts (scripts/github_index.py and scripts/pk_index.py) explicitly download public GitHub repo tarballs via the GitHub API (see fetch_tarball and the "API Access"/"Network" sections in SKILL.md) and parse README/markdown/notebooks/code to build indexes, meaning it ingests untrusted, user-generated repository content that the agent reads and uses to drive retrieval and project-knowledge decisions.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 24, 2026, 06:29 AM