prd-to-tickets
Warn
Audited by Snyk on Aug 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The workflow ingests only the user-provided PRD text (or a user-supplied reference) directly in step 1 (“Extract the PRD's required behaviour…” / “Read the PRD…”) before generating tickets, meaning outsider-authored free text is consumed without selecting a specific item beyond the provided PRD.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata