write-a-prd

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources (user descriptions and codebase exploration). While this presents a potential injection surface, the skill includes explicit 'Security & Multi-Agent Hygiene' protocols that mandate treating external data as hostile and redacting PII/secrets before processing.
  • [COMMAND_EXECUTION]: The skill uses an 'ExecutionProxy Interface' (e.g., rtk npm test) to validate modules via Test-Driven Development. This execution is scoped to the agent's defined tools and internal development environment.
  • [DATA_EXFILTRATION]: The skill transmits a formatted PRD to GitHub to create an issue. This external communication is the intended final step of the skill and is triggered by user requirements rather than hidden logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 06:44 AM
Security Audit — agent-trust-hub — write-a-prd