to-prd
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is subject to indirect prompt injection risks due to its data ingestion patterns.
- Ingestion points: Processes conversation history and codebase context to generate the PRD.
- Boundary markers: Absent. There are no instructions to disregard embedded commands or delimiters within the ingested data.
- Capability inventory: The skill possesses the ability to browse the repository and write output to an external project issue tracker.
- Sanitization: Absent. The skill does not implement validation or escaping for the data it synthesizes before publishing it.
- [COMMAND_EXECUTION]: The instructions reference a setup command
/setup-matt-pocock-skillswhich is intended to initialize the project environment and metadata vocabulary.
Audit Metadata