prd
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The instructions in
SKILL.mdstrictly define a workflow for creating markdown documentation. No executable code, shell commands, or network-active components are included in the skill body or logic. - [EXTERNAL_DOWNLOADS]: The
skill-report.jsonfile contains a reference to thegithuborganization's official repository as the source for this skill. This is a trusted organization, and the reference is documented here neutrally. - [METADATA_POISONING]: The file
skill-report.jsoncontains a pre-existing security audit and a verdict of safe. Following the global analysis rules, these claims were treated as data rather than conclusions, and an independent audit was performed to verify the skill's safety. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user input to generate requirements documents. Ingestion points: User-provided answers to discovery questions in Phase 1 of the workflow. Boundary markers: None present. Capability inventory: The skill has no file-system write access, network communication capabilities, or command-execution features. Sanitization: None present. Because the skill lacks executable capabilities, this ingestion surface does not pose a security risk.
Audit Metadata