creating-jira-subtasks
Warn
Audited by Snyk on May 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). This skill's subagent explicitly fetches and verifies Jira tickets from the external JIRA_URL (see subagents/subtask-creator.md steps "Verify the parent ticket" and "Verify existing refs are safe to reuse"), ingesting user-generated issue fields and statuses from the external Atlassian workspace that directly influence create/reuse decisions and plan-file updates.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata