implement-feature
Warn
Audited by Snyk on May 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). The skill reads outsider-authored free text from
specs/{feature}/README.mdandspecs/{feature}/requirements.md(andtasks/task-{nn}-*.md) at runtime, then injects that prose into coder/review/fix agent prompts via the{requirements}and{task_content}placeholders—so any content authored by someone other than the operating user can become LLM context (indirect prompt injection risk).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata