sdd-propose
Warn
Audited by Snyk on Jul 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). SKILL.md specifies receiving “exploration analysis (from sdd-explore) OR direct user description” from the orchestrator and then writing a
proposal.md, so at runtime the agent is likely fed free-form text that originates outside the agent (orchestrator/user), which can be treated as outsider-authored input being used in the LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata