write-a-prd
Pass
Audited by Gen Agent Trust Hub on Mar 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill follows its intended workflow of interviewing the user, analyzing the local repository, and using Linear integration to create issues. No security violations or malicious behaviors were found.
- [PROMPT_INJECTION]: The skill analyzes the codebase, which is a potential surface for indirect prompt injection if a source file contains malicious instructions designed to manipulate the PRD output or tool parameters.
- Ingestion points: Codebase exploration (SKILL.md, step 2).
- Boundary markers: None observed.
- Capability inventory: Linear MCP 'save_issue' tool (network operation).
- Sanitization: No explicit sanitization of codebase data is mentioned.
Audit Metadata