to-prd
Pass
Audited by Gen Agent Trust Hub on May 16, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The instructions provide a structured workflow for document generation without attempting to override system safety guidelines or agent constraints.
- [DATA_EXFILTRATION]: While the skill reads codebase context and writes to an issue tracker, these actions are essential for its primary function. No evidence of unauthorized data harvesting or transmission to external, untrusted domains was found.
- [REMOTE_CODE_EXECUTION]: No patterns involving the download or execution of external scripts or packages from untrusted sources were identified.
- [OBFUSCATION]: The content was analyzed for hidden characters, Base64 encoding, and homoglyphs; no obfuscated content or deceptive text was discovered.
- [INDIRECT_PROMPT_INJECTION]: The skill processes project information and conversation context. This represents a standard surface for processing external data, but the skill does not contain logic that would facilitate the execution of malicious instructions embedded in that data.
Audit Metadata