skills/kenlck/skills/to-prd/Gen Agent Trust Hub

to-prd

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's behavior is consistent with its stated purpose of document synthesis and publishing. No suspicious network activity, data exfiltration, or malicious commands were detected.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes codebase files and conversation history to generate output that is subsequently published to an issue tracker.\n
  • Ingestion points: SKILL.md (instructions), repository files, and user conversation context.\n
  • Boundary markers: Absent; there are no specific delimiters to prevent the agent from following instructions embedded in the analyzed data.\n
  • Capability inventory: The skill can write to the project's issue tracker.\n
  • Sanitization: Absent; the skill does not explicitly mention filtering or sanitizing the input data before inclusion in the PRD.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 05:06 AM
Security Audit — agent-trust-hub — to-prd