create-prd
Warn
Audited by Snyk on Aug 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 该技能在“Phase 0: Import Context / Phase 2: Gather Information”会读取用户提供的本地文件内容并将其作为预填充材料(再进一步让用户逐步回答问题)用于生成 PRD,因此存在用户/外部作者可通过“用户提供的文件”向运行流程注入自由文本的间接提示注入风险。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata