prd-maker
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is focused on generating structured product documentation and operates within a clearly defined and restricted directory structure (.hyper/prd/).
- [COMMAND_EXECUTION]: The skill utilizes local scripts (scripts/build-preview.mjs, scripts/render-planning-map.mjs) for rendering planning artifacts. These scripts use standard Node.js/Bun built-in modules for file I/O and string processing, and include basic HTML escaping for generated preview files.
- [PROMPT_INJECTION]: No override markers or jailbreak patterns were found in the instruction files. The skill follows a logical hierarchy where user context and project rules appropriately govern the output generation.
- [DATA_EXFILTRATION]: There are no indicators of unauthorized data collection or exfiltration. Credential management instructions emphasize the use of environment files (.env), which is a recommended security practice.
Audit Metadata