prd-creator
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill accepts implementation descriptions and wireframe images from users as primary inputs to generate documentation and task lists. This introduces a surface for indirect prompt injection where malicious instructions embedded in these inputs could influence the agent's behavior or be propagated into the generated code-ready tasks.
- Ingestion points: User-provided implementation descriptions (Part 1,
SKILL.md) and wireframe image analysis (PRD.md). - Capability inventory: The skill uses the
Readtool for files and images,WebSearchfor research, and performs various file writing operations (PRD.md,tasks.json,.env.local). - Boundary markers: There are no explicit delimiters or specific instructions provided to the agent to treat the user-supplied text or image content as untrusted data.
- Sanitization: No sanitization or validation of user-provided content is mentioned before it is processed by the agent.
- [COMMAND_EXECUTION]: In the task generation workflow (
JSON.md), the mandatory prerequisite verification task (TASK-1) instructs the agent to "Run the safest available read-only connectivity checks for the database and required services." This directive implies the execution of local shell commands or database client tools to verify the status of external services. - [DATA_EXFILTRATION]: The skill's prerequisite gate (
PRD.md) requires the agent to scan the repository for sensitive files, including.env,.env.example, and.env.local, to identify required environment variables. While the skill includes strict constraints against writing real secret values to any output or chat, the capability to read these sensitive paths represents a potential data exposure risk if the agent's instructions were to be bypassed.
Audit Metadata