gsd-plan-phase
Warn
Audited by Snyk on Jun 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). The skill’s runtime path ingests outsider-authored free text when it performs research by fetching/reading external sources (e.g., public web pages or other non-user documents) and then passes that readable text into the LLM context for planning/verification via the research→plan→verify loop.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata