prd-writer
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and process data from external issue trackers to generate or update PRDs. This creates an ingestion point for indirect prompt injection where malicious instructions embedded in a tracker issue could attempt to influence the agent's planning behavior. The risk is mitigated by the skill's enforcement of a specific Markdown structure and the use of 'Quality Gates' to validate content before processing.
- [SAFE]: No other security concerns were identified. The skill does not involve remote code execution, sensitive credential access, or unauthorized network activity. All external references are consistent with the identified vendor identity.
Audit Metadata