linear-implement
Warn
Audited by Snyk on Jul 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The required workflow reads the newest Linear “marked plan” comment (outsider-authored issue/comment text) and re-reads its
open_questions/accepted_unknowns/do_not_assumeto drive implementation, so that free-form content can enter the agent’s LLM context via the Linear MCPget_issue/list_comments→ plan parsing path.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata