doc-prd-autopilot
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a Python-based driver script located at
${CLAUDE_PLUGIN_ROOT}/tools/saga_driver.pyto orchestrate the generation and audit workflow. - [PRIVILEGE_ESCALATION]: The execution command includes the
--allow-skip-permissionsflag, which explicitly instructs the agent to bypass standard platform permission prompts for file writes to enable unattended execution. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by ingesting untrusted data to drive file generation and logic.
- Ingestion points: The skill accepts free-text prompts, BRD (Business Requirements Document) files, and IPLAN (Implementation Plan) files as primary inputs for generation (SKILL.md).
- Boundary markers: No explicit boundary markers or instructions to ignore embedded commands within the input data are defined in the orchestration logic.
- Capability inventory: The skill has the capability to execute shell commands via
saga_driver.pyand perform file system write operations to thedocs/02_PRD/directory (SKILL.md). - Sanitization: There is no evidence of sanitization or validation of the input content before it is processed by the generation driver.
Audit Metadata