Back to skill

Security audit

prd-generator-from-prototype

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only PRD-writing skill that stays aligned with generating scoped Chinese product requirement documents.

This skill appears safe to install for drafting PRDs, but users should avoid pasting sensitive proprietary prototype details unless they are comfortable having the agent use that content to generate the document.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.