to-prd
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill demonstrates a surface for indirect prompt injection due to the way it processes external data to generate documentation. \n
- Ingestion points: The skill reads from the current conversation context and the codebase understanding (repository files). \n
- Boundary markers: No explicit markers (e.g., XML tags or delimiters) are defined to separate user/repo content from system instructions. \n
- Capability inventory: The skill has the capability to explore the file system and publish content to an external issue tracker. \n
- Sanitization: The skill lacks explicit sanitization or validation steps for the data it ingests before processing it into the final PRD output.\n- [SAFE]: No evidence of malicious behavior such as hardcoded credentials, obfuscated code, remote script execution, or persistence mechanisms was found. The skill's primary operations align with its stated purpose of documentation generation.
Audit Metadata