doc-prd-audit
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PRD documents which could contain malicious instructions designed to influence the audit outcome.
- Ingestion points: Untrusted artifact paths (e.g.,
docs/02_PRD/...) and the document content itself. - Boundary markers: The skill implements a 'de-anchoring' strategy, explicitly instructing subagents to 'Disregard the author self-assessment score' and citing specific playbook checks to prevent anchoring or injection from the document's own metadata.
- Capability inventory: File system read/write operations, Bash utility command execution, and invocation of downstream skills (e.g.,
doc-prd-fixer). - Sanitization: Mitigation is handled via explicit instructions to the model to ignore specific metadata fields (e.g.,
*_ready_score,audit_score) in the untrusted input. - [COMMAND_EXECUTION]: The skill executes Bash shell commands to manage directories and track execution time for its break-circuit policy.
- Evidence: Use of
mkdir -pto prepare blackboard directories anddate +%sto implement a timeout mechanism. - These are utility commands used for lifecycle and state management within the agent framework and do not involve executing external or unvalidated remote code.
Audit Metadata