sh1-create

Warn

Audited by Snyk on Feb 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's "create" workflow explicitly fetches issues from third-party sources like GitHub and Jira and parses untrusted issue body text to detect dependencies ("Processing -> create: Fetch issues from specified sources" and "Detect dependencies from issue body text"), which can directly alter scheduling decisions and tool behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 28, 2026, 11:35 PM