review-prd

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of instructional markdown for reviewing documents. It does not contain any code, scripts, or subprocess calls, and it does not request any network or file system permissions.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted PRD content, creating a theoretical attack surface for indirect prompt injection. 1. Ingestion points: The skill analyzes user-provided PRD documents (SKILL.md). 2. Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the text. 3. Capability inventory: The skill has no active capabilities (no tool usage, network access, or shell execution). 4. Sanitization: The skill mandates that sensitive data be redacted from citations, but does not specify automated sanitization of document content. The overall risk is negligible due to the lack of capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 09:25 PM
Security Audit — agent-trust-hub — review-prd