work-tickets
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In SKILL.md the workflow uses a configured “tracker adapter” to load and read full ticket content and comments for the implementation worker (“Read the full ticket, comments…”), and it also selects/derives a frontier from the tracker state—so outsiders who can submit/poison ticket/comment text into the tracker can cause the agent to ingest free text at runtime.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata