git-review

Warn

Audited by Snyk on Jul 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). 该技能在 Phase 1 通过 git log/git diff/git show 读取仓库内提交的作者、提交信息与正文(--format="%H|%an|%ai|%s|%b|||"--name-status、以及 diff 统计),这些文本可能包含非操作用户作者的内容,从而以“git 仓库提交历史/变更文本”路径进入 LLM 上下文。

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 17, 2026, 12:52 AM
Issues
1
Security Audit — snyk — git-review