tasks-plan
Warn
Audited by Snyk on Mar 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's required workflow ("Fetch the specification") uses the Notion MCP to retrieve a user-provided Notion page and any linked pages—user-generated third-party content—which the agent must read and use to produce implementation plans and create tasks, so those pages could contain instructions that influence the agent's decisions.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill fetches and ingests a user-provided Notion page URL at runtime via the Notion MCP (a user-provided notion.so page URL), and that fetched content is used directly to drive the agent's planning instructions and outputs, so the external Notion URL can directly control agent prompts.
Audit Metadata