batch-linear-tickets

Warn

Audited by Snyk on May 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches and consumes user-generated Linear ticket data (see Step 1a: "Fetch each ticket's labels via mcp__claude_ai_Linear__get_issue") and then uses the investigator's Evidence Record and the Feature/Bug packs (which include "Sources" like ticket text, attached design docs, and user-supplied files) to drive classification, planning, and automated PR execution, so untrusted third‑party ticket/content can materially influence agent actions.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 17, 2026, 04:53 AM
Issues
1
Security Audit — snyk — batch-linear-tickets