prd-self-audit
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions are strictly task-oriented and do not contain patterns typical of prompt injection, such as attempts to bypass safety filters or disregard system instructions.
- [DATA_EXFILTRATION]: No network-enabled tools (e.g., curl, wget) are used. The skill is documented to be non-interactive and does not transmit data to external domains.
- [COMMAND_EXECUTION]: The skill does not utilize shell commands, subprocesses, or system-level APIs. Its functionality is limited to reading document prose and outputting a text report.
- [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote scripts or packages.
- [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or private credential paths are present in the skill files.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from PRDs and referenced files. While this represents a data ingestion surface, the risk is mitigated because the skill lacks exploitable capabilities like file modification or network access. Boundary markers are implicitly defined by the structured three-pass process and report format.
Audit Metadata