prd-planner
Fail
Audited by Snyk on Feb 15, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 1.00). The prompt includes an "Auto-Trigger" that instructs the skill to automatically invoke a background "self-improving-agent" and an automatic "session-logger" to extract patterns and save session context—actions that are unrelated to the explicit PRD creation workflow and could silently collect or exfiltrate data, so they are deceptive/out-of-scope instructions.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's Step 3 "Research & Analysis" explicitly instructs performing web searches (e.g.,
web search "best practices for {feature}") and saving those findings to the notes that the agent later reads and synthesizes into the PRD, thus consuming untrusted public web content.
Audit Metadata