to-prd
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its data processing flow.
- Ingestion points: The skill reads untrusted data from repository files and current conversation history during the exploration phase.
- Boundary markers: Absent; the instructions do not specify the use of delimiters or 'ignore' warnings to isolate external repository data from the agent's core logic.
- Capability inventory: The agent utilizes repository read access for codebase exploration and has the capability to publish content to an external project issue tracker (network/write access).
- Sanitization: Absent; there are no requirements provided to sanitize, escape, or validate the content extracted from the repository before it is formatted into the PRD template.
- [NO_CODE]: This skill consists solely of instructions and does not contain any executable scripts or binary files.
Audit Metadata