prd-to-issues
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources which could contain malicious instructions.
- Ingestion points: Data is ingested via
gh issue viewin Step 1, which reads the content and comments of GitHub issues. - Boundary markers: The instructions do not specify the use of delimiters or specific warnings to ignore instructions embedded within the PRD content.
- Capability inventory: The skill has the ability to read the codebase, create GitHub issues via
gh issue create, and potentially interact with other project tools. - Sanitization: There is no explicit sanitization or filtering of the ingested PRD content mentioned in the process.
- Mitigation: The process includes a mandatory human-in-the-loop (HITL) step (Step 4: Quiz the user) where the proposed breakdown must be approved before any issues are created, significantly reducing the risk of automated malicious actions.
Audit Metadata