to-prd
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill identifies and uses project-specific documentation and global configuration files to assist in PRD generation. No malicious behavior such as data exfiltration or unauthorized system access was found.- [PROMPT_INJECTION]: The skill processes conversation context to synthesize the PRD, which is a common pattern for documentation agents. While this creates an indirect prompt injection surface, it is limited by the skill's specific task focus.
- Ingestion points: Conversation context and repository files (CLAUDE.md).
- Boundary markers: Absent.
- Capability inventory: Reading local files and writing to the project issue tracker.
- Sanitization: Absent.
Audit Metadata