openclaw-secret-scanning-maintainer

Warn

Audited by Snyk on Apr 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's fetch-content command (documented in SKILL.md Step 1 and implemented in scripts/secret-scanning.mjs) pulls issue/PR/discussion/comment bodies from GitHub (user-generated, public content) into a body_file which the agent is explicitly required to read and use to decide redactions and follow-up actions, exposing it to untrusted third-party content that could contain malicious instructions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 24, 2026, 04:50 AM
Issues
1