gemini-review
Warn
Audited by Snyk on Jun 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Outsider free text is ingested via GitHub PR review-thread comment bodies (e.g.,
bodyText/bodyfromreviewThreads.nodes[].comments.nodes[]andpullRequest.comments.nodes[]) fetched at runtime byscripts/wait-pr-review.shandscripts/pr-review-summary.shusinggh api graphql, and then included in the agent’s context/output for classification.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata