to-prd
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's behavior is consistent with its stated purpose of document synthesis and publishing. No suspicious network activity, data exfiltration, or malicious commands were detected.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes codebase files and conversation history to generate output that is subsequently published to an issue tracker.\n
- Ingestion points: SKILL.md (instructions), repository files, and user conversation context.\n
- Boundary markers: Absent; there are no specific delimiters to prevent the agent from following instructions embedded in the analyzed data.\n
- Capability inventory: The skill can write to the project's issue tracker.\n
- Sanitization: Absent; the skill does not explicitly mention filtering or sanitizing the input data before inclusion in the PRD.
Audit Metadata