codex-review
Warn
Audited by Snyk on Aug 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The codex review workflow ingests outsider-authored free text indirectly only from first-party/codexradar network HTML/JSON fetched by
scripts/select-review-model.mjs(BASE_URL/SITE_URL), not from user- or third-party submissions into a queue/feed the workflow monitors.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata