org-orchestrate
Warn
Audited by Snyk on Mar 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches and ingests public GitHub repo metadata via
gh repo listand then clones and operates on selected public repos as described in Phase 1 (Repos) and Phase 2b/2c, so untrusted user-generated GitHub content can directly influence which actions and tools are run.
Audit Metadata