drive-pr
Warn
Audited by Snyk on Jul 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Yes—Phase 2 fetches outsider-authored PR issue comments/reviews/review-thread bodies via
gh api/GraphQL and then Phase 3b synthesizes LLM “finding” text from those comment bodies (even though untrusted comments are excluded from the exit gate, the workflow still reads them and can feed trusted-open comment text into the agent pipeline).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata