bmad-domain-research
Warn
Audited by Snyk on Apr 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's required workflow (SKILL.md and the domain-steps/*.md files, e.g., step-02-domain-analysis.md, step-03-competitive-landscape.md, step-04-regulatory-focus.md) explicitly mandates live "Search the web" queries, citation of URLs, and immediate incorporation of web search findings into decisions and generated documents, meaning it fetches and ingests open/public (potentially untrusted/user-generated) content that can materially influence tool actions and outputs.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata