NYC

sred-project-organizer

Warn

Audited by Snyk on Feb 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill prompts for and consumes external Notion/GitHub/Linear documents at runtime (e.g. the example Notion work summary https://www.notion.so/sentry/SRED-Work-Summary-2026-30a8b10e4b5d81f5bc8df3553da55220), and those fetched documents are injected into the agent’s context to directly drive its summarization/classification logic — meeting the criteria for an external content-controlled prompt risk.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 19, 2026, 09:20 PM