to-prd
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing external conversation data without sufficient safeguards.
- Ingestion points: The skill explicitly takes the current conversation context as input to synthesize the PRD (SKILL.md).
- Boundary markers: There are no delimiters or instructions provided to the agent to distinguish between legitimate requirements and malicious instructions embedded in the conversation context.
- Capability inventory: The skill has the capability to explore the codebase (read) and publish content to an external issue tracker in Linear (write).
- Sanitization: There is no evidence of input validation or sanitization of the conversation context before it is used to generate the published output.
Audit Metadata