pm-prd-writer

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs text transformation and document structuring tasks without any executable code, network operations, or sensitive file system access.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted user data such as meeting minutes and chat screenshots. This creates an indirect prompt injection surface where instructions embedded in the input could attempt to influence the PRD's content. However, the skill lacks high-risk capabilities like shell access or network requests, so any potential impact is confined to the generated text and document quality.
  • Ingestion points: Processes user-uploaded requirement descriptions, meeting minutes, and chat transcripts in the 'Clarify' phase.
  • Boundary markers: The skill uses a structured four-phase workflow and explicit templates to guide the agent, though it does not explicitly instruct the model to ignore instructions inside the provided data.
  • Capability inventory: Limited to generating text and Mermaid diagrams. No file-writing (outside of platform-native docx handling if available), network operations, or subprocess calls were found.
  • Sanitization: No explicit sanitization or filtering of input data is defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 07:46 AM
Security Audit — agent-trust-hub — pm-prd-writer