code-reviewer
Warn
Audited by Snyk on May 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). This skill ingests user-contributed repository/PR content (see "Review current changes", "Direct GitHub code links" and the workflow/tools allowing Read/Grep/Glob) so external/untrusted GitHub code can be read and materially influence the agent's analysis and outputs.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata