architecture-review
Warn
Audited by Snyk on Jun 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Runtime path: Step 1 loads PR content via
gh pr view ... --json ... ,bodyandgh pr diff ..., which ingests outsider-authored PR body/diff text into the agent context for review.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata