wibaek-review-diff-scan

Warn

Audited by Snyk on Jul 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). 이 스킬은 PR/commit/working-tree diff를 읽고(“changed file과 changed line을 먼저 읽는다”, “focused git diff”), 그 diff/파일 내용이 LLM 컨텍스트로 들어가는데, 해당 diff 텍스트는 PR 작성자(outsider)가 제공한 변경사항일 수 있어 outsider-authored free text(코드/주석/문자열 포함)가 런타임에 LLM에 주입될 위험이 있습니다.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 3, 2026, 01:48 AM
Issues
1
Security Audit — snyk — wibaek-review-diff-scan