pm-spec-writing

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of documentation and templates for writing Product Requirements Documents (PRDs). No malicious patterns, obfuscation, or data exfiltration attempts were detected.
  • [COMMAND_EXECUTION]: The skill configuration allows access to the 'Bash' tool. However, the markdown body does not contain any shell commands or instructions to execute external scripts. The tool access is likely intended to facilitate the saving and management of specification files within the specified docs/specs/ directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user input into structured PRDs. While it lacks explicit sanitization instructions for that input, its primary purpose is document generation, and it does not interpolate this data into sensitive tool calls or system commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 07:20 PM
Security Audit — agent-trust-hub — pm-spec-writing