brief
Warn
Audited by Snyk on Jun 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Runtime LLM context is populated from repo diffs/commit messages and (in FINAL mode) PR bodies/comments fetched via
gh pr view ... --json .../--comments; those PR/issue/comment texts are authored by outsiders, so they can include free-form prompt-injection content.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata