spec-product-prd

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs text-based document transformation between local files. No malicious patterns or security risks were identified in the skill's instructions or template.\n- [DATA_EXFILTRATION]: No network communication or data exfiltration patterns were detected. The skill only accesses project-specific Markdown files within a user-defined directory and does not touch sensitive system files or credentials.\n- [REMOTE_CODE_EXECUTION]: The skill does not download external scripts, install packages, or utilize dynamic execution functions. It relies entirely on templated text generation.\n- [PROMPT_INJECTION]: The skill does not contain instructions to override safety filters or agent behavior. It was evaluated for indirect prompt injection as it processes external project files, but the restricted write-only capability for Markdown content poses no significant risk.\n
  • Ingestion points: {FEATURE_DIR}/requirements/solution.md, {FEATURE_DIR}/requirements/raw.md via file-reading instructions.\n
  • Boundary markers: Absent.\n
  • Capability inventory: Writing Markdown content to {FEATURE_DIR}/requirements/prd.md. No network or shell execution capabilities.\n
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 08:09 AM
Security Audit — agent-trust-hub — spec-product-prd