skills/sahyll/juspay-skills/jp-prd/Gen Agent Trust Hub

jp-prd

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from external Juspay documentation and user codebases, creating a surface for indirect prompt injection. \n
  • Ingestion points: Data fetched via 'docs-mcp-server' (external URLs) and local files read during 'Codebase + env scan'. \n
  • Boundary markers: Uses '[ASSUMPTION]' tags and source URL citations to demarcate derived facts. \n
  • Capability inventory: Performs file writing for PRDs and reports, and executes system commands to open local HTML files. \n
  • Sanitization: No explicit sanitization is mentioned for external content before it is synthesized into the HTML validation report. \n- [COMMAND_EXECUTION]: The skill automates the opening of generated HTML reports using system-level shell commands. \n
  • Evidence: 'references/validate.md' instructs the agent to execute 'open' (macOS) or 'xdg-open' (Linux) on the generated 'validation-report.html' file.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 09:39 AM
Security Audit — agent-trust-hub — jp-prd