to-prd
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted content from the local repository and conversation history to create entries in an issue tracker, creating an indirect injection surface. \n- Ingestion points: Local codebase files and current conversation context as referenced in SKILL.md. \n- Boundary markers: Absent; no specific instructions or delimiters are provided to the agent to separate legitimate instructions from potential data-embedded commands in the analyzed files. \n- Capability inventory: Permission to synthesize content and publish it to a project issue tracker using available tools. \n- Sanitization: Absent; the skill does not specify any validation or sanitization steps for the source text before it is synthesized into a PRD and published.
Audit Metadata