refactor-plan-gate
Warn
Audited by Snyk on Jul 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). Outsider free text can enter the LLM context via the runtime diagnosis/spec-kit checkpoint: the skill detects
.specify/and then consumes existing project-authored spec artifacts (spec.md/plan.mdand related.specify/content) as part of the plan in Mode 1/3, which are not authored by the operating user.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata