address-gemini-feedback
Warn
Audited by Snyk on Mar 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches GitHub PR review threads via the agentTool (see "Fetch unresolved comments" step using ./scripts/agents/tooling/agentTool.ts getReviewThreads) and reads user-generated review comment bodies, which the agent must interpret to decide fixes and replies, exposing it to untrusted third-party content.
Audit Metadata