Back to skill

Security audit

Prd Cross Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed PRD analysis helper that reads scoped local product/API reference material and writes a PRD document, with no hidden code or destructive behavior found.

Before installing, make sure you are comfortable with the agent reading the referenced local competitor/API materials and saving a generated PRD into the catering-saas-prd project tree. Confirm any Feishu sync explicitly and review the generated PRD for proprietary or sensitive business content before sharing it.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
94% confidence
Finding
The skill directs the agent to save generated output to a local file by default, but does not require explicit user confirmation before performing the write. This can cause unintended filesystem modifications, especially when the user only asked for analysis and did not authorize persistence.

Static analysis

No suspicious patterns detected.