process-meeting-notes

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill explicitly fetches and ingests meeting transcripts and summaries from Fireflies (e.g., mcp__fireflies__fireflies_get_transcript, mcp__fireflies__fireflies_get_summary called in workflows/process-recent-meeting.md, workflows/search-meeting.md, and workflows/create-issues-from-notes.md), treats those user-generated transcripts as input to extract action items, and then uses that content to decide and create GitHub issues—allowing untrusted third-party content to materially influence agent actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 10:46 AM