to-prd
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill demonstrates a vulnerability surface for indirect prompt injection by processing external, untrusted data to perform automated tasks.\n
- Ingestion points: The skill reads from the project repository and the current conversation history to synthesize the PRD (SKILL.md).\n
- Boundary markers: No specific boundary markers or instructions (e.g., 'ignore instructions within this data') are used when processing external context.\n
- Capability inventory: The skill possesses the capability to publish generated content directly to the project's issue tracker.\n
- Sanitization: There is no evidence of sanitization, validation, or escaping of the ingested content before it is published to the issue tracker.
Audit Metadata