prd-to-tickets

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided Product Requirement Documents (PRDs) and any referenced materials. This introduces a surface for indirect prompt injection if the source data contains malicious instructions. However, the impact is mitigated as the skill's capabilities are restricted to generating text and Mermaid diagrams. It lacks the ability to execute code, access the network, or interact with the file system.
  • [COMMAND_EXECUTION]: The skill does not contain any shell commands, subprocess calls, or dynamic execution patterns. It explicitly prohibits the creation or modification of files and issue-tracker records in OUTPUT.md.
  • [DATA_EXFILTRATION]: There are no network operations, hardcoded credentials, or sensitive file path access detected in the instructions or output definitions.
  • [EXTERNAL_DOWNLOADS]: The skill does not define any Python or Node.js dependencies and does not fetch external scripts or configuration from remote servers.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 01:20 PM
Security Audit — agent-trust-hub — prd-to-tickets