prd-task-creator

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill focuses on structured task creation and PRD management using legitimate tools and workflows. No malicious patterns, obfuscation, or unauthorized data access were detected.
  • [COMMAND_EXECUTION]: The skill utilizes the GitHub CLI (gh) to automate issue management. These operations are transparent, described in the documentation, and limited to standard repository interactions.
  • [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it reads existing GitHub issues and local documentation which could contain malicious instructions. However, the risk is neutralized by a mandatory human-in-the-loop approval step (Step 6: Get approval before creating) where the user must review any generated draft before the agent executes commands or writes files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 01:29 PM
Security Audit — agent-trust-hub — prd-task-creator