gh-fix-ci
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's script and workflow fetch and parse GitHub-hosted, user-generated CI content (e.g., via
gh pr checks,gh run view --log, andgh api /repos/.../actions/jobs/.../logsin scripts/inspect_pr_checks.py) and then extracts and summarizes log snippets for the agent to read, which exposes it to untrusted third-party content.
Audit Metadata