write-a-prd

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes extensive user-provided input without specific boundary markers, which technically creates an attack surface for indirect prompt injection. However, since the primary function is document generation and the skill explicitly forbids external network communication, the risk is minimal. 1. Ingestion points: Step 1 in SKILL.md solicits long, detailed input from the user. 2. Boundary markers: No explicit delimiters or boundary markers are defined to isolate untrusted user input from the agent's instructions. 3. Capability inventory: The skill allows for repository exploration and writing to local files (issues/prd.md). 4. Sanitization: No explicit sanitization or validation of the ingested user input is specified.
  • [SAFE]: The skill includes explicit instructions to the agent to avoid calling external services or submitting issues to GitHub, ensuring that data remains within the local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:36 PM
Security Audit — agent-trust-hub — write-a-prd