prd
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were identified during the analysis. The skill's workflow involves reading codebase files to understand existing patterns and writing a markdown document to the project root, both of which are standard operations for a developer productivity tool.
- [PROMPT_INJECTION]: The skill analyzes codebase files, which constitutes a surface for indirect prompt injection (Category 8). However, given the skill's focus on document generation and the absence of high-risk capabilities like network access or shell execution based on that data, the risk is negligible. Ingestion points: codebase files (SKILL.md, Workflow step 3); Boundary markers: absent; Capability inventory: file read (codebase exploration) and file write (PRD generation); Sanitization: absent.
Audit Metadata