create-prd

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust 'Documentation-Only Scope' policy that explicitly forbids the agent from editing source code, running build/migration commands, or modifying system configurations. This acts as a strong internal safeguard against unintended implementation actions.
  • [SAFE]: File system access is restricted to reading relevant project documentation (such as product briefs and research files) and writing new PRD documents to the 'docs/' directory. No access to sensitive system files or credentials was detected.
  • [SAFE]: The skill uses established internal orchestration patterns, calling other specific skills like 'create-doc' and 'pm-checklist' for its functional logic without introducing external code dependencies or remote script execution.
  • [SAFE]: No obfuscation, data exfiltration patterns, or prompt injection vulnerabilities were identified in the skill's instructions or metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:01 AM
Security Audit — agent-trust-hub — create-prd