jp-prd
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from external Juspay documentation and user codebases, creating a surface for indirect prompt injection. \n
- Ingestion points: Data fetched via 'docs-mcp-server' (external URLs) and local files read during 'Codebase + env scan'. \n
- Boundary markers: Uses '[ASSUMPTION]' tags and source URL citations to demarcate derived facts. \n
- Capability inventory: Performs file writing for PRDs and reports, and executes system commands to open local HTML files. \n
- Sanitization: No explicit sanitization is mentioned for external content before it is synthesized into the HTML validation report. \n- [COMMAND_EXECUTION]: The skill automates the opening of generated HTML reports using system-level shell commands. \n
- Evidence: 'references/validate.md' instructs the agent to execute 'open' (macOS) or 'xdg-open' (Linux) on the generated 'validation-report.html' file.
Audit Metadata