review
Warn
Audited by Snyk on Jul 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The skill’s runtime path reads the changed files and diffs via
git diffand “Read each changed file in full” in the review subagent, so if the diff includes outsider authored text (for example PR/issue content or files authored by someone other than the operating user), that free text is ingested into the subagent’s LLM context for review.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata