foreman-to-prd — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited foreman-to-prd (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
(Adapted from mattpocock/skills to-prd — see NOTICE. Removed: live "check with the user" seam confirmation and the GitHub publish + ready-for-agent label step. Output is a local prd.md file, not a tracker post.)
This skill is the PRD template authority. The foreman-grill-docs skill calls it to produce prd.md. Synthesize from the approved plan, the codebase, and the grilled decisions — do NOT interview anyone.
the project's domain glossary (CONTEXT.md) throughout, and respect ADRs in the area you're touching.
seams; use the highest seam possible. If a new seam is needed, propose it at the highest point you can — and if whether that seam is acceptable is a genuine product/architecture call you cannot settle from the code, add it to the ## Open questions for reviewer block rather than asking interactively.
prd.md into the feature directory using the template below. Begin thefile with the open-questions block (see foreman-grill-docs). Do not publish anywhere and do not apply any labels.
<prd-template>
<unresolved product/architecture questions, or "_None — all resolved._">
The problem the user is facing, from the user's perspective.
The solution to the problem, from the user's perspective.
A LONG, numbered list of user stories, each: As an <actor>, I want a <feature>, so that <benefit>. Extremely extensive — cover all aspects of the feature. These stories are the basis for the slicer (foreman-to-issues) and for the e2e flows, so make each one concrete and verifiable.
For each end-to-end flow a user can perform, list the ordered steps and the observable outcome. These flows are what Foreman's e2e phase will turn into automated tests, so be precise about preconditions, steps, and expected results.
Modules built/modified, interfaces changed, technical clarifications, architectural decisions, schema changes, API contracts, specific interactions. No file paths or code snippets (they go stale) — exception: a prototype-derived snippet that encodes a decision more precisely than prose (state machine, reducer, schema, type shape) may be inlined, trimmed to the decision-rich parts.
What makes a good test here (test external behavior, not implementation details); which modules will be tested; prior art for the tests (similar tests already in the codebase); the test/lint/typecheck commands Foreman will run to verify work.
What is explicitly not part of this PRD.
Anything else worth recording.
</prd-template>
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.