to-prd
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it incorporates external repository data and conversation history into its output.\n
- Ingestion points: Repository file system (via exploration) and conversation context.\n
- Capability inventory: Repository exploration (file read) and GitHub issue submission (network write).\n
- Boundary markers: None identified in the skill instructions.\n
- Sanitization: No explicit instructions provided for sanitizing or escaping ingested content before submission to GitHub.
Audit Metadata