cria-prd

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill reads a local template from assets/prd-template.md and writes output to ./tasks/prd-[feature-slug]/prd.md. These file operations are restricted to the local project environment and do not involve unauthorized data transmission or access to sensitive system files.
  • [SAFE]: The skill uses tools like 'AskUserQuestion' and 'Web Search'. It does not perform arbitrary shell command execution or attempt to escalate privileges.
  • [SAFE]: The skill ingests user input for feature descriptions and clarification answers (SKILL.md). While this untrusted data is used to generate the final PRD, the use of a predefined template and the specific focus on functional requirements effectively manage the risk of indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 03:23 AM
Security Audit — agent-trust-hub — cria-prd