code-review-web
Warn
Audited by Snyk on Jul 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). The required workflow explicitly ingests “the code, PR, error message, or symptom under review” and “access to logs” (runtime-provided by the user’s selected PR/issues/logs), which can include outsider-authored free text such as PR/issue descriptions or log excerpts; this text is then used as LLM context for the review.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata