gds-code-review
Warn
Audited by Snyk on Jul 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Yes: Step 1 gathers the review target from the triggering conversation (Tier 1/2) and can load user-provided “provided diff or file list” into
{diff_output}, which is then fed into subagents’ LLM prompts (e.g., Blind Hunter receives{diff_output}only; Edge Case/Acceptance Auditor receive{diff_output}plus spec/context), so outsider-authored free text from the user’s message can become LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata