skills/yldgio/vibe-grimoire/prd-slice/Gen Agent Trust Hub

prd-slice

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill features a potential surface for indirect prompt injection because it fetches and processes untrusted data from external platforms.
  • Ingestion points: PRD content is retrieved using gh issue view (in references/github.md) and az boards work-item show (in references/azure-devops.md).
  • Boundary markers: No specific delimiters or instructions are provided to the agent to distinguish between the PRD text and system instructions.
  • Capability inventory: The skill can create new work items and establish relationships using gh issue create and az boards work-item create across the tracker reference files.
  • Sanitization: The skill does not implement sanitization or filtering on the content retrieved from the trackers.
  • [COMMAND_EXECUTION]: The skill correctly uses established command-line tools (gh and az) to perform project management tasks. The commands are scoped to the intended functionality of reading and creating work items, and they incorporate best practices such as explicitly specifying repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 05:32 PM