bmad-domain-research

Warn

Audited by Snyk on Apr 22, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's required workflow (SKILL.md and the domain-steps/*.md files, e.g., step-02-domain-analysis.md, step-03-competitive-landscape.md, step-04-regulatory-focus.md) explicitly mandates live "Search the web" queries, citation of URLs, and immediate incorporation of web search findings into decisions and generated documents, meaning it fetches and ingests open/public (potentially untrusted/user-generated) content that can materially influence tool actions and outputs.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 22, 2026, 03:39 AM
Issues
1