prd-generator

Fail

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/generate_prd.sh script utilizes eval on unsanitized user input, enabling arbitrary command execution. An attacker can provide input containing single quotes and semicolons to run shell commands outside the intended variable assignment.
  • [COMMAND_EXECUTION]: The scripts/generate_prd.sh script uses a user-controlled variable for file redirection (cat > "$OUTPUT_FILE"). This permits an attacker to overwrite sensitive system files or configuration files by providing a malicious file path.
  • [DYNAMIC_EXECUTION]: The skill performs dynamic shell command construction and execution via eval, which introduces high-risk vulnerabilities when interacting with external or user-provided data.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 25, 2026, 08:06 AM
Security Audit — agent-trust-hub — prd-generator