to-prd
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates entirely through natural language instructions to the AI agent. It does not include any scripts, external dependencies, or command execution patterns.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external data such as conversation logs, user-supplied artifacts, and repository files to generate a PRD. While this presents a surface for indirect prompt injection, the risk is mitigated as the skill's output is limited to text documentation within the repository and does not involve executing code derived from these inputs.
- Ingestion points: Processes user briefs, conversations, and existing repository evidence (SKILL.md).
- Boundary markers: None explicitly defined, but the instructions focus on analytical output.
- Capability inventory: File writing (docs/-prd.md) and repository reading.
- Sanitization: Relies on the base LLM's safety guardrails.
Audit Metadata