to-prd

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing external codebase data. Ingestion points: Repository files and conversation history referenced in SKILL.md. Boundary markers: None defined to isolate external data from the PRD template instructions. Capability inventory: Repository exploration tools and issue tracker publication. Sanitization: No sanitization or escaping mechanisms are described for the external content.
  • [SAFE]: The skill includes a human-in-the-loop validation step ('Check with the user') which reduces the risk of automated malicious actions. The external references are for attribution purposes and do not involve untrusted code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 07:25 AM
Security Audit — agent-trust-hub — to-prd