confluence

Warn

Audited by Snyk on Mar 1, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The SKILL.md shows the agent performs reads/searches against a Confluence instance (e.g., af confluence get, search, comments, attachments using the JIRA_BASE_URL) which ingests user-generated wiki pages, comments, and attachments that the agent will read and could materially influence subsequent actions like updates, labeling, or publishing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 1, 2026, 03:28 PM