prd-to-tasks

Fail

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: Detection of homoglyph substitution in documentation placeholders.\n
  • Evidence: The placeholder <prд-mentioned-symbol> in SKILL.md uses the Cyrillic character 'д' (U+0434) instead of the Latin 'd'.\n- [COMMAND_EXECUTION]: The skill executes shell commands to analyze the codebase and retrieve documents.\n
  • Evidence: Invokes grep, find, and lark-cli across several phases (Phase 1.0 and Phase 2 in SKILL.md).\n- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection from processed PRDs.\n
  • Ingestion points: PRD content from Lark/Feishu URLs, pasted text, and local files (Phase 0 and 1.0 in SKILL.md).\n
  • Boundary markers: Includes <HARD-GATE> sections requiring explicit human approval strings to proceed.\n
  • Capability inventory: Performs file reads/writes and codebase-wide searching via shell commands.\n
  • Sanitization: Relies on human-in-the-loop review rather than automated input sanitization.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: Performs network requests to fetch external documentation.\n
  • Evidence: Uses lark-cli to fetch data from well-known services feishu.cn and lark.cn (Phase 1.0 in SKILL.md).
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
May 17, 2026, 04:51 PM
Security Audit — agent-trust-hub — prd-to-tasks