to-prd

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were detected in the skill instructions.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by processing conversation data. 1. Ingestion points: The agent is instructed to use the current conversation history. 2. Boundary markers: The instructions lack explicit delimiters for the conversation input. 3. Capability inventory: The agent is permitted to explore the repository and publish content to an external issue tracker. 4. Sanitization: No explicit sanitization or filtering of the conversation content is performed. The use of a strict PRD template acts as a mitigation by constraining the output format.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 06:18 PM
Security Audit — agent-trust-hub — to-prd