skills/evans-sam/skills/write-a-prd/Gen Agent Trust Hub

write-a-prd

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by fetching and processing content from external, potentially attacker-controlled sources (Linear tickets, Figma designs, Notion pages) using MCP tools.
  • Ingestion points: In Step 2, the skill fetches rich context from external URLs or identifiers provided by the user. If these external documents contain malicious instructions, the agent may follow them while attempting to 'form a more complete picture' of the project.
  • Boundary markers: There are no explicit boundary markers or instructions telling the agent to treat the fetched content as untrusted or to ignore any embedded directives.
  • Capability inventory: The skill possesses capabilities to read the local codebase (Step 3) and write to various destinations, including local file paths, GitHub wikis, and Notion/Confluence pages (Step 6). Maliciously injected instructions could attempt to abuse these read/write capabilities to exfiltrate sensitive code or data.
  • Sanitization: The skill does not implement any sanitization or validation logic for the content retrieved from external services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:18 AM
Security Audit — agent-trust-hub — write-a-prd