trello

Warn

Audited by Snyk on Aug 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The Trello skill’s runtime ingests outsider-authored free text by reading card/list comments and descriptions from the user’s Trello via endpoints like /cards/{cardId}/actions?filter=commentCard and /boards/{boardId}/cards (including .data.text), which can originate from any user who can post to those Trello cards/boards.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 20, 2026, 04:31 PM
Issues
1
Security Audit — snyk — trello