review

Warn

Audited by Snyk on Jul 29, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The skill reads outsider-authored free text from GitHub PRs it is instructed to review (e.g., gh pr view ... --json ... body,files and the PR comment/review threads via gh api repos/<owner>/<repo>/pulls/<number>/reviews / .../comments), which are attacker-controlled by anyone who can create or update that PR.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 29, 2026, 09:37 AM
Issues
1
Security Audit — snyk — review