receiving-code-review
Warn
Audited by Snyk on Mar 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The SKILL.md workflow explicitly requires the agent to "Read" and act on feedback from "external reviewers (PR comments, open source)" and "GitHub PR Reviews," which are untrusted, user-generated third-party PR comments that the agent is expected to interpret and can materially change its actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata