babysit-pr

Warn

Audited by Snyk on Jul 25, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). Outsider free text from GitHub PR discussion content—specifically issue_comment.body, pulls/<pr_number>/comments bodies, and pulls/<pr_number>/reviews bodies by other authors—is fetched at runtime via gh api in fetch_new_review_items() / normalize_*() and then included in the emitted watcher snapshot (which the agent consumes), creating an indirect prompt-injection path through scripts/gh_pr_watch.pynew_review_items → LLM context.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 25, 2026, 04:46 AM
Issues
1
Security Audit — snyk — babysit-pr