to-prd
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from the conversation history and repository content to generate a PRD. This creates a surface for indirect prompt injection if the ingested data contains instructions designed to manipulate the generated output or the publishing process.
- Ingestion points: Reads current conversation context and codebase files (SKILL.md).
- Boundary markers: None identified in the instructions.
- Capability inventory: Uses tool access to publish content to a project issue tracker.
- Sanitization: No specific sanitization or filtering of the source data is mentioned before publishing.
Audit Metadata