blueprint-prp-create

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill employs the Bash tool and dynamic context injection (the ! command syntax) to execute project-discovery commands such as find and jq. These operations are limited to the project's documentation and manifest directories (docs/blueprint, docs/prds) and are used to gather necessary context for requirement generation.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes WebSearch and WebFetch tools to retrieve external technical documentation and best practices for libraries and frameworks. This is a primary function of the research phase and targets legitimate documentation sources.
  • [SAFE]: No malicious patterns, such as prompt injection, data exfiltration, obfuscation, or persistence mechanisms, were identified. The use of development tools and network access is well-scoped to the intended project management and documentation workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 04:18 PM
Security Audit — agent-trust-hub — blueprint-prp-create