soia-dev-design-draft-prd

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a pure methodology-based agent for requirement drafting. It does not perform network operations, access sensitive file paths, or request excessive permissions.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill documentation explicitly states that it does not read unauthorized company knowledge bases, account data, or personal data. It defaults to generating drafts within the conversation and only writes to disk if explicitly directed by the user to a specific location.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns were detected. The skill uses standard package managers (npm, npx, claude plugin) for installation from a known vendor repository.
  • [PROMPT_INJECTION]: No malicious prompt injection patterns were found. The instructions focus on structured output and maintaining logical boundaries (e.g., distinguishing facts from assumptions).
  • [EXTERNAL_DOWNLOADS]: The installation instructions reference the soia-team GitHub repository, which is consistent with the skill's authorship. These are standard installation procedures for the platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 08:02 AM
Security Audit — agent-trust-hub — soia-dev-design-draft-prd