code-review
Warn
Audited by Snyk on Aug 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The skill’s required workflow only ingests user-supplied review material (code diff/patch, code identity, and optional role reports) provided in the request, and has no runtime path that reads outsider-authored external feeds/queues/bug trackers/browsed pages without the user first selecting/pasting the specific content.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata