prd-delivery

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external Product Requirement Documents (PRDs) to define subagent tasks, creating a surface where malicious requirement content could influence agent operations. * Ingestion points: The Orchestrator subagent reads the provided PRD in SKILL.md to decompose it into tasks. * Boundary markers: No explicit delimiters or instructions are provided to the agents to isolate or ignore instructions embedded within the PRD data. * Capability inventory: Spawns Implementation agents with file modification capabilities and a Refactoring agent that uses code-related skills. * Sanitization: The instructions do not specify any validation or sanitization for the content processed from the PRD.
  • [COMMAND_EXECUTION]: Implementation agents are tasked with making changes to the codebase. While the skill orchestrates this through subagent delegation, it grants those subagents broad permission to modify implementation files based on the PRD requirements without explicit tool limitations or sanitization at the orchestration layer.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 03:08 PM
Security Audit — agent-trust-hub — prd-delivery