recipe-pr-review

Fail

Audited by Snyk on Aug 25, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (medium risk: 0.30). This is a GitHub PR-review automation recipe that contains instructions to run nested LLM reviewers and explicitly to bypass or escalate sandbox/permission checks (weakening security boundaries) but does not contain clearly malicious exfiltration or payload delivery.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Source: GitHub PRs—runtime path collect-pr-context.py calls gh pr view/gh pr diff and paginates PR issue comments, review comments, and reviews (/repos/{owner}/{repo}/pulls/{number}/comments, /issues/{number}/comments, /pulls/{number}/reviews), then get-review-material.py/run-review.py feeds this PR-derived free text into the reviewer LLM.

Issues (2)

E004
CRITICAL

Prompt injection detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 25, 2026, 04:25 PM
Issues
2
Security Audit — snyk — recipe-pr-review