escrever-prd

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data, creating a theoretical surface for indirect prompt injection.
  • Ingestion points: The skill reads existing PRD files from ./docs/prds/ and accepts user-provided descriptions via the $ARGUMENTS variable.
  • Boundary markers: The instructions do not specify any delimiters or safety markers to differentiate between user data and system instructions when processing existing files.
  • Capability inventory: The skill's actions are limited to reading and writing Markdown files. It has no capabilities for network access, shell command execution, or dynamic code evaluation.
  • Sanitization: No explicit sanitization or filtering of input data is defined before the content is used to generate the document draft. However, given that the output is plain text documentation, the risk is negligible.
  • [SAFE]: No malicious patterns were detected. The skill does not use network tools (curl, wget), does not attempt privilege escalation, and contains no obfuscated code or remote dependencies. Its operations are strictly limited to document management within the local project workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:12 PM
Security Audit — agent-trust-hub — escrever-prd