to-prd
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local binary to display the generated documentation to the user.
- Evidence: SKILL.md contains a PowerShell command
Start-Process -FilePath "$env:LOCALAPPDATA\plannotator\plannotator.exe" -ArgumentList @('annotate', '<absolute-path>')to open the draft. - Note: This is a functional component of the skill intended to facilitate document review.
- [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests and processes data from external sources like GitHub PRs and Linear tickets.
- Ingestion points: Phase 1 in SKILL.md resolves inputs from pull requests, tickets, and session history.
- Boundary markers: No explicit boundary markers or delimiters are defined to isolate untrusted external content from the agent's instructions.
- Capability inventory: The skill can write markdown files to the local repository and execute a local annotation tool.
- Sanitization: No evidence of sanitization or validation of external content is documented before processing.
Audit Metadata