ncode-prd
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user input during the Q&A phase and writes it directly into a
PRD.mdfile. This creates an attack surface where a user could provide instructions disguised as product details that may be executed by other agents or tools reading the document later. - Ingestion points: User responses to the six discovery questions in 'Phase 1' of the skill.
- Boundary markers: The
PRD.mdoutput template lacks data delimiters or safety instructions to distinguish user-provided text from agent instructions. - Capability inventory: The skill utilizes file system write capabilities to create the
PRD.mdfile in the project root. - Sanitization: No input validation, escaping, or sanitization logic is applied to the user's answers before they are saved to the project file system.
Audit Metadata