to-prd
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. It ingests untrusted data from the codebase and conversation context and uses this to generate content for a write operation (publishing to an issue tracker). \n
- Ingestion points: The skill reads conversation context and performs repository exploration to understand the project state.\n
- Boundary markers: None identified. There are no instructions for the agent to ignore directives or instructions embedded within the codebase data it processes.\n
- Capability inventory: The agent has the ability to explore the filesystem (read) and publish content to an external issue tracker (write).\n
- Sanitization: None identified. The skill does not provide instructions for validating or escaping content retrieved from the repository before publication.\n- [NO_CODE]: The skill consists entirely of instructional content in the SKILL.md file and does not include any executable scripts, packages, or binaries, which significantly reduces the risk of direct malicious code execution.
Audit Metadata