prd-task-creator

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes potentially untrusted external data (feature requests, bug reports, planning documents) which could contain hidden instructions designed to manipulate the agent during the PRD generation phase.
  • Ingestion points: Data enters the context through user-provided feature/bug descriptions in SKILL.md (Step 2) and references/full-guide.md (Agent brief structure).
  • Boundary markers: The skill lacks explicit delimiters or specific 'ignore-embedded-instructions' warnings to separate the untrusted input from the agent's core logic.
  • Capability inventory: The skill is authorized to use the GitHub CLI (gh tool) for issue creation, branch development, and API interactions, and has write access to the .agents/memory/ and .out-of-scope/ directories.
  • Sanitization: Although the skill uses secure shell patterns (quoted heredocs) to prevent technical command injection at the OS level, there is no semantic sanitization to prevent the agent from following natural language instructions found within the input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — prd-task-creator