write-a-prd
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions are purely functional and intended for documentation generation. No malicious code, obfuscation, or unauthorized data access patterns were detected.
- [PROMPT_INJECTION]: The skill incorporates information from the repository's codebase to generate the PRD. While this creates an ingestion point for external data, it is a primary function of the skill and no malicious intent was observed.
- Ingestion points: Local repository files (Step 2 in SKILL.md).
- Boundary markers: None specified in the instructions.
- Capability inventory: Agent-provided file system research tools.
- Sanitization: No explicit sanitization or filtering of codebase content is mentioned.
Audit Metadata