tui-prd-to-descriptions

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional and documentation-oriented. It defines a workflow for transforming text input into specific text-based outputs (ASCII art, Markdown, and structured plans) without executing shell commands or scripts.
  • [SAFE]: No sensitive data access or credential patterns were detected. The documentation includes a security best-practice recommendation to avoid hardcoding sensitive information in environment variables.
  • [EXTERNAL_DOWNLOADS]: The skill contains a reference to a GitHub documentation page for an external project (partme-ai/stitch-skills) to provide context for output formats. This is a neutral reference to a public repository on a well-known service.
  • [DATA_EXFILTRATION]: There are no network-capable tools or commands present that could be used for data exfiltration. The skill defines its boundaries clearly, stating it only produces description text and does not call external MCPs.
  • [PROMPT_INJECTION]: The skill does not contain instructions that attempt to bypass safety filters or override the agent's core identity. It focuses strictly on formatting and mapping PRD data to specific schemas.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 04:14 AM
Security Audit — agent-trust-hub — tui-prd-to-descriptions