prd-generator
Fail
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/generate_prd.shscript utilizesevalon unsanitized user input, enabling arbitrary command execution. An attacker can provide input containing single quotes and semicolons to run shell commands outside the intended variable assignment. - [COMMAND_EXECUTION]: The
scripts/generate_prd.shscript uses a user-controlled variable for file redirection (cat > "$OUTPUT_FILE"). This permits an attacker to overwrite sensitive system files or configuration files by providing a malicious file path. - [DYNAMIC_EXECUTION]: The skill performs dynamic shell command construction and execution via
eval, which introduces high-risk vulnerabilities when interacting with external or user-provided data.
Recommendations
- AI detected serious security threats
Audit Metadata