release-tag

Warn

Audited by Snyk on Apr 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The workflow explicitly runs git pull (git pull origin ) and inspects remote/commit data via git log and tags, which can ingest untrusted, potentially public repository commits or messages that the agent reads and uses to decide version bumps and subsequent commands.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 1, 2026, 09:20 AM
Issues
1