write-a-prd
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from both the user and the repository codebase, which could contain malicious instructions designed to influence the agent's behavior during the PRD creation process.
- Ingestion points: The agent is instructed to "Explore the repo" and "Ask the user for a long, detailed description" (SKILL.md).
- Boundary markers: The instructions lack explicit delimiters or warnings to treat the codebase content as non-executable data.
- Capability inventory: The agent has the ability to read the entire repository and write content to external GitHub issues.
- Sanitization: There are no defined processes to sanitize or filter potential instructions embedded within the codebase or user feedback before they are used to generate the PRD output.
Audit Metadata