to-prd
Warn
Audited by Snyk on Aug 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). Required workflow “to-prd” resolves the input by reading “a PR, a Linear or GitHub ticket” and “the current session, the repo, the PR, the ticket” to ground facts, which implies it ingests outsider-authored free text contained in those issue/PR/ticket bodies at runtime.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata