develop-task

Warn

Audited by Snyk on May 14, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly reads user-generated tracker content as part of Phase 0 (e.g., Phase 0a uses gh issue view to fetch GitHub issue bodies and parse DOC_URL, and the tracker-state-poller/subagent reads PR/issue comments and Jira issue fields) and then uses that content to resolve file paths, decide pipeline steps, and drive subsequent tool/sub-skill invocations, so untrusted third-party content can materially influence actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 14, 2026, 07:01 AM
Issues
1
Security Audit — snyk — develop-task