onboard
Warn
Audited by Snyk on Apr 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's inline agents explicitly ingest public GitHub content—Troubleshooting searches "GitHub Discussions/Wiki" and Next Steps runs
gh issue listto read open GitHub issues—so it reads untrusted, user-generated pages and uses their content to drive onboarding recommendations and next actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata