skills/hk-hub/agentskills/prd-to-plan/Gen Agent Trust Hub

prd-to-plan

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process PRDs which are external, potentially untrusted documents that may contain instructions meant to subvert the agent's behavior.
  • Ingestion points: The skill explicitly instructs the agent to confirm the PRD is in context or ask the user to provide it (Step 1).
  • Boundary markers: There are no instructions for the agent to use delimiters or ignore embedded commands within the PRD, increasing the risk of the agent following malicious instructions hidden in the requirement text.
  • Capability inventory: The agent is authorized to explore the codebase (Step 2) and write files to the local filesystem (Step 6).
  • Sanitization: No sanitization or validation logic is defined to prevent the PRD content from influencing the file-writing or codebase exploration tasks.
  • [COMMAND_EXECUTION]: The instruction to "explore the codebase" (Step 2) necessitates the use of system commands to traverse directories, read source files, and analyze project structure. While standard for development tasks, this provides a capability surface that could be abused if directed by an injected prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — prd-to-plan