idea-to-prd
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses detailed instructional language to guide the AI's behavior for PRD generation. No patterns associated with bypassing safety filters, system prompt extraction, or ignoring instructions were detected.
- [DATA_EXFILTRATION]: No network operations or commands to access sensitive local files (like .env or .ssh) are present.
- [REMOTE_CODE_EXECUTION]: The skill does not perform any remote code downloads or execution. It functions entirely as a text-to-text transformation tool.
- [COMMAND_EXECUTION]: There are no shell commands or subprocess calls within the instructions or metadata.
- [OBFUSCATION]: The content is provided in clear text (Chinese and English). No hidden characters, Base64 encoding, or homoglyphs were identified.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided product ideas to generate documentation. While this represents a data ingestion surface, the skill lacks any execution capabilities (such as file writes or API calls) that could be exploited via malicious input. The risk is limited to content generation quality.
Audit Metadata