code-to-prd

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external source code to reverse-engineer business requirements, creating a vulnerability surface where instructions embedded in comments or data could influence the model.
  • Ingestion points: The agent reads local source files, manifests (package.json, manage.py), and project structures from a user-provided directory.
  • Boundary markers: The skill instructions do not utilize specific delimiters or instructions to isolate the codebase content as untrusted data, potentially allowing acrostics or hidden instructions in comments to trigger unintended behavior.
  • Capability inventory: The skill uses provided scripts to scan files and write a new directory structure (prd/) to the project root containing generated documentation.
  • Sanitization: Although the codebase analyzer script uses regex for structured metadata extraction, the workflow requires the agent to semantically analyze raw source code, which lacks automated sanitization against malicious injection content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:53 AM