requesting-code-review
Warn
Audited by Snyk on Jul 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required workflow dispatches the
superpowers:code-reviewersubagent with user/tenant-provided placeholders (e.g.,{WHAT_WAS_IMPLEMENTED},{DESCRIPTION}, and git SHAs) and then reviews code viagit diff/git range, so it ingests repository content authored by outsiders (e.g., PR/commit text) when your workflow is triggered to review changes.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata