深度集成 Gitee MCP,实现 Issue 管理、PR 自动化提交、代码审查和版本发布的全流程自动化。
Security
1 medium severity finding. This skill can be installed but you should review these findings before use.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
Third-party content exposure detected (high risk: 0.80). The skill's SKILL.md explicitly calls Gitee MCP APIs that fetch repository files, issues, PR details, diffs, and search results (e.g., mcp_gitee_get_file_content, mcp_gitee_list_repo_issues, mcp_gitee_get_pull_detail, mcp_gitee_get_diff_files), which ingest untrusted user-generated content from Gitee and use that content to summarize, make decisions, and auto-generate PRs—allowing indirect prompt-injection via third-party pages/metadata.
6770aaa
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.