fix-coderabbit-review
Warn
Audited by Snyk on Aug 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
fix-coderabbit-review, Step 1 runsscripts/pr_review.pywhich fetches outsider-authored PR review/comment bodies and thread text from GitHub REST/GraphQL (/repos/{owner}/{repo}/pulls/{pr_number}/comments,/issues/{pr_number}/comments, andreviewThreads), then reads and processes the generated markdown files (ai-docs/reviews-pr-<PR_NUMBER>/_summary.mdandissues/*.md) at runtime.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata