prd-development
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill is composed of markdown-based instructions, templates, and examples designed to guide a user through a product management workflow.
- [REMOTE_CODE_EXECUTION]: No remote script downloads, package installations (npm, pip, etc.), or dynamic execution patterns (eval, exec) were found in the provided files.
- [DATA_EXFILTRATION]: The skill does not perform network operations (curl, wget, fetch) or access sensitive system files (e.g., .ssh, .aws, .env).
- [PROMPT_INJECTION]: The facilitation protocol uses standard interaction patterns (guided vs. context dump) and does not contain instructions to bypass safety filters or ignore previous system prompts.
- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to ingest external user data (such as Slack threads or discovery notes), it lacks dangerous capabilities—such as shell execution or external network writes—that could be exploited via malicious input in those notes.
- [COMMAND_EXECUTION]: No shell commands or dynamic context injection patterns (!
command) are present in any of the analyzed files.
Audit Metadata