implement-feature

Warn

Audited by Snyk on May 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). The skill reads outsider-authored free text from specs/{feature}/README.md and specs/{feature}/requirements.md (and tasks/task-{nn}-*.md) at runtime, then injects that prose into coder/review/fix agent prompts via the {requirements} and {task_content} placeholders—so any content authored by someone other than the operating user can become LLM context (indirect prompt injection risk).

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 28, 2026, 05:50 PM
Issues
1
Security Audit — snyk — implement-feature