to-prd

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate project management tasks. It is designed to explore a repository, analyze conversations, and use a structured template to create documentation. The actions described, such as reading ADRs (Architecture Decision Records) and publishing to an issue tracker, are standard development workflows.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from the conversation history and the codebase to generate its output. This constitutes an indirect prompt injection surface where malicious instructions embedded in those sources could attempt to influence the synthesized PRD. This is a low-risk surface inherent to the skill's primary purpose of data synthesis and is mitigated by the use of a strict markdown template.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 12:41 PM
Security Audit — agent-trust-hub — to-prd