prd-generator

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional and generates documentation based on user-provided inputs. There are no executable scripts, shell commands, or network-enabled tools associated with this skill. It specifically includes boundaries preventing the agent from drafting implementation code or setting up project folders.
  • [DATA_EXPOSURE]: The skill demonstrates security awareness by including non-functional requirements in its templates that advise against storing secrets or credentials in client-side code.
  • [PROMPT_INJECTION]: The skill processes untrusted external data (MVP Scope, Vision Document). While it lacks explicit boundary markers for these inputs, the impact is minimal as the skill's output is restricted to Markdown text with no downstream execution capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 11:30 AM
Security Audit — agent-trust-hub — prd-generator