prd-to-goal

Warn

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to generate shell-executable assertions for verifying project state. These include file system operations like test -f, checking line counts with wc, searching files with grep, and performing Git operations with gh. It also utilizes rm to manage internal state files for verification loops.- [DYNAMIC_EXECUTION]: Section 8 defines a pattern for a "Post-timeout assertion grader" that dynamically spawns a sub-agent by executing the claude CLI through the Bash tool. The command CLAUDE_CODE_FORK_SUBAGENT=1 claude -p --bare "$(cat /tmp/grader-prompt.txt)" reads a prompt from a temporary file created at runtime and executes it in a fresh context.- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data to generate instructions for subsequent agent loops, creating a surface for injection attacks.
  • Ingestion points: External data is ingested from user-provided PRD text, GitHub issue bodies via gh issue view, and local specification files via the Read tool.
  • Boundary markers: The skill lacks explicit boundary markers or isolation instructions to prevent the agent from adopting commands or logic embedded within the source text.
  • Capability inventory: The environment allows the use of Bash, Write, Read, and Agent tools across all functional scripts.
  • Sanitization: There is no evidence of sanitization or input validation to filter potentially malicious instructions from the source documents before they are transformed into goal assertions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 22, 2026, 07:44 AM
Security Audit — agent-trust-hub — prd-to-goal