jira-connector
Warn
Audited by Snyk on Aug 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). In the Jira connector’s runtime, the only outsider-authored free text it ingests comes from explicit user-provided parameters/files for comment/create/edit (e.g.,
--body-file,--description,--adf-file,--fields-json,--field), while reads (get,comments,search) just consume Jira issue/comment content selected by the user’s chosen issue key or JQL—there is no “queue/feed ingestion” path that an outsider can poison without the user selecting/fetching specific items.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata