pull
Warn
Audited by Snyk on Mar 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The SKILL.md workflow (steps 4–6: "git fetch origin", "git pull --ff-only origin ...", and "merge origin/main" — noting "for example, a GitHub auto-commit") requires fetching and interpreting remote repository commits from the origin remote (e.g., external GitHub commits), which the agent must read and act on when resolving conflicts.
Audit Metadata