prd-generator

Warn

Audited by Socket on Sep 25, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/generate_prd.sh

The code is a benign PRD generation utility, but it contains a command-injection vulnerability because interactive input is assigned through eval. It also permits arbitrary writable-path file output through the user-controlled OUTPUT_FILE value. Replace eval with safe variable assignment or nameref-based assignment, and validate or constrain the output path to an intended directory. No evidence of malware, exfiltration, persistence, or intentional sabotage is present.

Confidence: 99%Severity: 72%
Audit Metadata
Analyzed At
Sep 25, 2026, 08:06 AM
Package URL
pkg:socket/skills-sh/nicepkg%2Fai-workflow%2Fprd-generator%2F@381cc13f1da3215c52d954f89e48a5b42564b750f863594ec7804c3cece50b9d
Security Audit — socket — prd-generator