code-review
Warn
Audited by Snyk on Jun 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The workflow ingests outsider-authored free text when it reads PR/issue diffs or git history content (e.g.,
gh pr diff N --name-only/git log -p/ file reads), which can include code/comments authored by external contributors and then becomes LLM-readable prose in the “Read & Analyze” and “Generate Report” steps.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata