resolve-human-reviews

Warn

Audited by Snyk on Mar 8, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches and reads human review comments from the current PR using the agent-reviews CLI (see "Step 1: Fetch All Human Comments" — npx agent-reviews --humans-only --unanswered --expanded) and then interprets those reviewer comments to decide fixes, commits, and replies, so untrusted user-generated GitHub PR content can materially influence agent actions and enable indirect prompt injection.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 8, 2026, 11:00 AM