subagent-driven-development
Warn
Audited by Snyk on Aug 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In SKILL.md the workflow’s controller step “Read plan, extract all tasks with full text, note context, create TodoWrite” then dispatches subagents with the “[FULL TEXT of task from plan]” and uses it in both implementer and reviewer prompts, meaning outsider-authored free text is only exposed if the plan/tasks input can be populated by an external user at runtime (otherwise it’s first-party/tenant-controlled).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata