do-create-prd
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows secure practices by explicitly forbidding the execution of code, tests, or servers during the PRD creation process.
- [COMMAND_EXECUTION]: The skill performs file system operations such as reading templates and writing documentation. These operations are restricted to the project's PRD directory and internal skill asset paths, which is consistent with its stated purpose of document generation.
- [EXTERNAL_DOWNLOADS]: The instructions mention using Web Search for researching business rules. This is a standard non-malicious capability for AI agents used to gather information rather than to download or execute remote code.
- [PROMPT_INJECTION]: While the skill uses strong instructional language such as 'CRITICAL' and 'MANDATORY', these are used to maintain workflow consistency and ensure adherence to directory naming conventions, not to bypass safety guidelines or override the agent's core instructions.
Audit Metadata