address-pr-review
Warn
Audited by Snyk on Aug 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In Step 1 the runtime ingests PR and review comment free text from GitHub by calling
gh pr view/diff/review listand the GitHub API endpoint for pull request comments (repos/<owner>/<repo>/pulls/<PR-number>/comments), where commenters are outsiders.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata