pm-prd-write

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's footprint aligns with its stated purpose of generating PRDs from initiative descriptions using templates and a controlled two-phase workflow. There are no evident malicious patterns, credential handling, or external data flows that would indicate supply-chain risk. Overall, the artifact appears benign with respect to security risk, assuming the local scripts and templates are trusted and maintained within the Claude environment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 08:36 PM
Package URL
pkg:socket/skills-sh/parhumm%2Fjaan-to%2Fpm-prd-write%2F@ed6b473f5edc0d5a112b15a67e21da3a45d71ca4