doc-prd-audit

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PRD documents which could contain malicious instructions designed to influence the audit outcome.
  • Ingestion points: Untrusted artifact paths (e.g., docs/02_PRD/...) and the document content itself.
  • Boundary markers: The skill implements a 'de-anchoring' strategy, explicitly instructing subagents to 'Disregard the author self-assessment score' and citing specific playbook checks to prevent anchoring or injection from the document's own metadata.
  • Capability inventory: File system read/write operations, Bash utility command execution, and invocation of downstream skills (e.g., doc-prd-fixer).
  • Sanitization: Mitigation is handled via explicit instructions to the model to ignore specific metadata fields (e.g., *_ready_score, audit_score) in the untrusted input.
  • [COMMAND_EXECUTION]: The skill executes Bash shell commands to manage directories and track execution time for its break-circuit policy.
  • Evidence: Use of mkdir -p to prepare blackboard directories and date +%s to implement a timeout mechanism.
  • These are utility commands used for lifecycle and state management within the agent framework and do not involve executing external or unvalidated remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:18 PM
Security Audit — agent-trust-hub — doc-prd-audit