NYC

prd-planner

Fail

Audited by Snyk on Feb 15, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 1.00). The prompt includes an "Auto-Trigger" that instructs the skill to automatically invoke a background "self-improving-agent" and an automatic "session-logger" to extract patterns and save session context—actions that are unrelated to the explicit PRD creation workflow and could silently collect or exfiltrate data, so they are deceptive/out-of-scope instructions.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's Step 3 "Research & Analysis" explicitly instructs performing web searches (e.g., web search "best practices for {feature}") and saving those findings to the notes that the agent later reads and synthesizes into the PRD, thus consuming untrusted public web content.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 15, 2026, 08:50 PM