Skip to content

Conversation

@danenania
Copy link
Contributor

Testing the @mention trigger for code scans

@danenania
Copy link
Contributor Author

@promptfoo-scanner-staging please scan this PR

@promptfoo-scanner-staging
Copy link

❌ Failed to trigger code scan. The workflow file promptfoo-code-scan.yml may not exist or may not have workflow_dispatch enabled.

Copy link

@promptfoo-scanner-staging promptfoo-scanner-staging bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 All Clear

I reviewed the new test file src/test-comment-trigger.ts which adds a function that constructs prompts by concatenating user input. While the code pattern resembles prompt injection, no actual LLM security vulnerabilities were found because the function is not integrated into any LLM workflow—it has no callers and makes no LLM API calls. The code is an isolated test utility without an active exploit path.

Minimum severity threshold for this scan: 🟡 Medium | Learn more


Was this helpful?  👍 Yes  |  👎 No 

@danenania
Copy link
Contributor Author

@promptfoo-scanner-staging

1 similar comment
@danenania
Copy link
Contributor Author

@promptfoo-scanner-staging

@danenania
Copy link
Contributor Author

@promptfoo-scanner-staging scan please

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants