coderabbit-code-review
Warn
Audited by Snyk on May 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill runs the external CodeRabbit CLI which sends diffs to the CodeRabbit service and instructs the agent to read and act on the resulting review.txt (CodeRabbit output), i.e., untrusted third-party content from coderabbit.ai is ingested and can influence decisions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata