to-prd
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a set of instructions and a template for the agent to follow when summarizing project information. No malicious intent or suspicious patterns were detected in the instructions.
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests untrusted data from the conversation history and codebase to populate a PRD template. While it lacks explicit boundary markers to isolate this data, the risk is minimal and inherent to the functionality of a summarization tool.
- [COMMAND_EXECUTION]: The instructions refer to a setup command,
/setup-utarn-skills, which is used to initialize the environment. This is a vendor-provided command (author: utarn) and is considered a legitimate part of the skill suite's configuration process.
Audit Metadata