prd-generator
Warn
Audited by Socket on Sep 25, 2026
1 alert found:
SecuritySecurityscripts/generate_prd.sh
MEDIUMSecurityMEDIUM
scripts/generate_prd.sh
The code is a benign PRD generation utility, but it contains a command-injection vulnerability because interactive input is assigned through eval. It also permits arbitrary writable-path file output through the user-controlled OUTPUT_FILE value. Replace eval with safe variable assignment or nameref-based assignment, and validate or constrain the output path to an intended directory. No evidence of malware, exfiltration, persistence, or intentional sabotage is present.
Confidence: 99%Severity: 72%
Audit Metadata