openclaw-secret-scanning-maintainer
Warn
Audited by Snyk on Apr 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's fetch-content command (documented in SKILL.md Step 1 and implemented in scripts/secret-scanning.mjs) pulls issue/PR/discussion/comment bodies from GitHub (user-generated, public content) into a body_file which the agent is explicitly required to read and use to decide redactions and follow-up actions, exposing it to untrusted third-party content that could contain malicious instructions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata