to-prd
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses repository data and chat history as input, which represents an indirect prompt injection surface. This is expected behavior for its primary function.\n
- Ingestion points: Conversation context and repository files (SKILL.md).\n
- Boundary markers: Absent; no delimiters are defined to isolate untrusted content from internal logic.\n
- Capability inventory: Reading repository content and publishing to an external issue tracker.\n
- Sanitization: No sanitization of ingested content is explicitly instructed.\n- [COMMAND_EXECUTION]: The skill references a slash command
/setup-matt-pocock-skillsfor setting up tracking and labels, which is an internal reference to another skill within the environment.
Audit Metadata