skills/canhassancode/skills/to-prd/Gen Agent Trust Hub

to-prd

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill identifies and uses project-specific documentation and global configuration files to assist in PRD generation. No malicious behavior such as data exfiltration or unauthorized system access was found.- [PROMPT_INJECTION]: The skill processes conversation context to synthesize the PRD, which is a common pattern for documentation agents. While this creates an indirect prompt injection surface, it is limited by the skill's specific task focus.
  • Ingestion points: Conversation context and repository files (CLAUDE.md).
  • Boundary markers: Absent.
  • Capability inventory: Reading local files and writing to the project issue tracker.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 12:54 PM
Security Audit — agent-trust-hub — to-prd