manage-prd-docs

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill demonstrates high autonomy by instructing the agent to 'automatically merge and clean up' and 'not wait for user' confirmation for file system operations, including the deletion of work directories. This reduces user oversight for destructive actions within the documentation folders.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its ingestion of content from various repository documents.
  • Ingestion points: The agent reads AGENTS.md, docs/index.md, and multiple PRD markdown files across the docs/ directory structure (SKILL.md).
  • Boundary markers: The instructions lack definitions for delimiters or safety markers to isolate potentially malicious instructions embedded in these external documents.
  • Capability inventory: The agent is empowered to read, write, move, and delete files and directories within the repository's documentation scope, and it executes auditing tools on these files.
  • Sanitization: There are no specified procedures for sanitizing or validating content retrieved from documentation files before the agent processes and acts upon it.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 08:50 AM
Security Audit — agent-trust-hub — manage-prd-docs