semi-formal-code-review

Warn

Audited by Snyk on Apr 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's Scope Discovery explicitly instructs the agent to "fetch the PR diff and summary from the available repo or platform tools" and the Exploration Protocol requires reading every file touched by the diff—i.e., ingesting PRs/patches which are untrusted, user-generated third-party content that the agent must interpret and which can materially influence its review decisions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 1, 2026, 11:53 PM
Issues
1