skills/evans-sam/skills/prd-to-issues/Gen Agent Trust Hub

prd-to-issues

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project requirements from external, potentially untrusted sources which can influence the agent's task generation behavior.
  • Ingestion points: The skill reads PRD content and external context from local files, GitHub wiki pages, Notion, Confluence, Linear issues, and Figma designs as described in steps 1 and 2 of SKILL.md.
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate the fetched PRD content from the agent's core logic or to prevent the agent from following instructions embedded within the PRD.
  • Capability inventory: The agent has the capability to write to the local file system, create GitHub issues via the gh CLI, and interact with Notion and Linear via MCP tools.
  • Sanitization: The instructions do not specify any validation or sanitization of the external document content before it is interpolated into issue templates or passed to tool commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:21 AM
Security Audit — agent-trust-hub — prd-to-issues