plan-qa
Warn
Audited by Snyk on Jul 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). This workflow fetches outsider-authored Linear issue text (title/description/acceptance criteria) at runtime via
mcp__plugin_linear_linear__get_issue, then instructs using that content to generate the test plan that becomes LLM context and is later attached/executed by/qa.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata