extract-my-action-items
Warn
Audited by Snyk on Mar 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches and ingests user-generated meeting transcripts from Fireflies (Phase 2: "Call
mcp__fireflies__fireflies_get_transcript" and the MCP/API extraction steps) and then has the agent read and act on that transcript to decide ticket/Slack actions, so untrusted third-party transcript content can materially influence follow-up tool use and actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata