yy-create-prd
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Potential indirect prompt injection surface found in PRD update logic. Ingestion points: The skill reads content from existing PRD files specified by the user (SKILL.md Step 2 and 5). Boundary markers: The instructions do not define delimiters or specific safety warnings to distinguish external file content from agent instructions. Capability inventory: The skill has the capability to write and modify Markdown files in the local filesystem (SKILL.md Step 5). Sanitization: No sanitization or validation of the ingested PRD content is performed before it is processed or used to generate new document versions.
Audit Metadata