task

Warn

Audited by Snyk on Mar 5, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly reads task data from third-party backends (e.g., beans list --json, linear issue list, gh issue list and task bodies referenced in commands/analyse.md and update.md) and uses those user-generated task bodies to decide actions (e.g., whether to mark complete, include summaries, archive), exposing the agent to untrusted external content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 5, 2026, 12:28 PM