reproduce-bug
Warn
Audited by Snyk on Apr 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill explicitly ingests and reads user-generated content from external tracker sources (Linear issues via "Linear MCP reads" and GitHub issue threads using "gh issue view" to fetch titles, bodies, comments, and attachments), and directs the agent to use that content to drive reproduction steps and follow-up actions, which could allow indirect prompt injection.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata