babysitting-prs
Warn
Audited by Snyk on Aug 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The skill’s required workflow reads outsider-authored free text from GitHub pull request review threads and comments at runtime via
scripts/pr_babysit.sh status -> review_threads_graphql_json(GraphQLreviewThreads.comments.body) andstate_json(issue/pr commentsbody, reviewbody) that are then included in the JSON fed to the LLM for deciding how to respond/fix.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata