write-a-prd

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The instructions provide a logical framework for requirement gathering and do not contain malicious commands, obfuscation, or unauthorized data access patterns.
  • [PROMPT_INJECTION]: The skill surface includes processing external data from the repository and user interview responses to generate PRD content for GitHub issues. This represents a potential surface for indirect prompt injection, but the behavior is consistent with the primary use case.
  • Ingestion points: User-provided problem descriptions (Step 1) and repository codebase content (Step 2).
  • Boundary markers: None defined.
  • Capability inventory: Read access to the codebase and write access to GitHub issues.
  • Sanitization: None defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 02:39 AM
Security Audit — agent-trust-hub — write-a-prd