backlog-execute
Warn
Audited by Snyk on Aug 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In SKILL.md “Required Flow” Step 2–4, this command ingests and processes a “planner-produced artifact”/“handoff file” into create/update/link/comment operations while explicitly treating item bodies/comments and fetched platform payloads as untrusted content, meaning outsider-authored free text can be included via the user-supplied handoff artifact that the workflow reads at runtime.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata