to-prd
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXFILTRATION]: The skill facilitates sending summarized project information to GitHub Issues. This is the primary intended function of the skill and involves a well-known service. The process includes a safeguard where the agent is instructed not to include specific code snippets or file paths in the PRD, reducing the risk of unintentional data exposure.- [PROMPT_INJECTION]: The skill processes untrusted input from the conversation context and codebase. This presents an indirect prompt injection surface where instructions hidden in the codebase could attempt to manipulate the generated PRD. However, the risk is minimized by the use of a fixed template and a workflow that requires the agent to check with the user before final submission.- [SAFE]: No malicious patterns such as obfuscation, persistence mechanisms, or unauthorized privilege escalation were detected.
Audit Metadata