sdd
Warn
Audited by Snyk on Aug 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). SKILL.md runs bundled
scripts/assess-sdd-state.py .to read untrusted repository-local spec/task/audit/validation markdown files (including potentially outsider-authored content in those files) and routes/loads only bundled phase references afterward.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata