review-pull
Warn
Audited by Snyk on Jun 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The skill is “Review Pull Request” and its runtime workflow (e.g.,
tea pulls review,tea pulls review-comments,tea pulls 15 --fields diff,patch) necessarily ingests PR diff/patch and comment text from the target repository/PR, which is outsider-authored content (other users’ PRs/comments) delivered via the platform’s APIs into the agent’s LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata