NYC

github-release-manager

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill uses the GitHub CLI and API (e.g., COMMITS=$(gh api repos/owner/repo/compare/${LAST_TAG}...HEAD --jq '.commits[].commit.message'), gh release list/download, gh pr create) to fetch commit messages, release notes, and assets from GitHub repositories—user-generated/public content that the agent ingests to build changelogs and releases, which can carry untrusted instructions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 08:13 PM