to-prd

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its data processing flow.
  • Ingestion points: The skill reads untrusted data from repository files and current conversation history during the exploration phase.
  • Boundary markers: Absent; the instructions do not specify the use of delimiters or 'ignore' warnings to isolate external repository data from the agent's core logic.
  • Capability inventory: The agent utilizes repository read access for codebase exploration and has the capability to publish content to an external project issue tracker (network/write access).
  • Sanitization: Absent; there are no requirements provided to sanitize, escape, or validate the content extracted from the repository before it is formatted into the PRD template.
  • [NO_CODE]: This skill consists solely of instructions and does not contain any executable scripts or binary files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 04:32 PM
Security Audit — agent-trust-hub — to-prd