prd-to-goal
Warn
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to generate shell-executable assertions for verifying project state. These include file system operations like
test -f, checking line counts withwc, searching files withgrep, and performing Git operations withgh. It also utilizesrmto manage internal state files for verification loops.- [DYNAMIC_EXECUTION]: Section 8 defines a pattern for a "Post-timeout assertion grader" that dynamically spawns a sub-agent by executing theclaudeCLI through theBashtool. The commandCLAUDE_CODE_FORK_SUBAGENT=1 claude -p --bare "$(cat /tmp/grader-prompt.txt)"reads a prompt from a temporary file created at runtime and executes it in a fresh context.- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data to generate instructions for subsequent agent loops, creating a surface for injection attacks. - Ingestion points: External data is ingested from user-provided PRD text, GitHub issue bodies via
gh issue view, and local specification files via theReadtool. - Boundary markers: The skill lacks explicit boundary markers or isolation instructions to prevent the agent from adopting commands or logic embedded within the source text.
- Capability inventory: The environment allows the use of
Bash,Write,Read, andAgenttools across all functional scripts. - Sanitization: There is no evidence of sanitization or input validation to filter potentially malicious instructions from the source documents before they are transformed into goal assertions.
Audit Metadata