prd-quality-gate

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external trackers and repository files (such as issue bodies, comments, and source code) to validate project readiness. This capability creates a theoretical surface where malicious instructions embedded in requirement text could influence the agent's logic. However, the skill provides a strong defensive framework. 1. Ingestion points: Live issue bodies, comments, and repository source files as specified in the SKILL.md contract. 2. Boundary markers: The skill mandates a 'Requirements SHA256' digest to anchor plans to specific requirement versions and utilizes 'Current plan:' identification URLs to distinguish current state. 3. Capability inventory: Explicitly restricted to read-only repository and tracker inspection; the skill claims no implementation or tracker mutation capabilities. 4. Sanitization: Includes text normalization for hash calculation (CRLF to LF conversion, whitespace trimming) but lacks explicit security-focused escaping of external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 12:11 PM
Security Audit — agent-trust-hub — prd-quality-gate