requirements-clarity
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a file-writing tool to save the generated PRD to the local filesystem at a specific path (
./docs/prds/{feature-name}-v{version}-prd.md). This is the intended primary purpose of the skill and follows standard development practices for documentation generation. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input (vague feature requests) and interpolates it into prompts for iterative clarification. While this creates a surface for prompt injection, the risk is mitigated by the skill's structured methodology, focused questioning (2-3 questions at a time), and the specific requirement that the output must be a structured markdown document (PRD) rather than executable code.
Audit Metadata