prd-risk-nfr-review

Review draft PRDs for security, privacy, NFR, and operational readiness gaps.

Updated Mar 22, 2026
One-click install
npx skills add https://github.com/TECH-HY/SKILLS --skill prd-risk-nfr-review-tech-hy
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: prd-risk-nfr-review
Source: https://github.com/TECH-HY/SKILLS/tree/main/skills/prd-risk-nfr-review
Command: npx skills add https://github.com/TECH-HY/SKILLS --skill prd-risk-nfr-review-tech-hy

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Draft PRDs often miss non-functional requirements, security controls, privacy handling, and operational readiness details, which leads to launch failures, rework, and trust-damaging incidents discovered too late. ## Core Features & Use Cases - Structured Risk Review: Evaluates a PRD across security, privacy, permissions, auditability, reliability, observability, and abuse scenarios with Critical/Major/Minor severity levels. - Concrete Amendments: Produces specific text blocks and requirements to add to the PRD rather than generic warnings. - Use Case: Before handing a fintech or marketplace PRD to engineering, run this review to surface missing audit trail, access control, and rollback requirements and get a launch-readiness verdict. ## Quick Start Use the prd-risk-nfr-review skill to review this draft PRD for risk, NFRs, and operational readiness.

Frequently Asked Questions about prd-risk-nfr-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review a PRD for security and privacy risks?

Provide the draft PRD and the skill walks through security, privacy, permissions, sensitive data handling, and audit trail dimensions. It outputs severity-ranked gaps with specific recommended amendments to add to the document.

What non-functional requirements should a PRD include?

A PRD should cover performance, reliability, security, privacy, auditability, and observability. This review checks each NFR area and identifies what is missing or needs clarification before engineering handoff.

When should I run a PRD risk review?

Run it after a draft PRD exists but before engineering handoff, especially for products with identity, KYC, payments, marketplaces, moderation, or operator-assisted workflows. It is not intended for writing a PRD from scratch.

Does the PRD review rewrite my requirements document?

No, the review does not rewrite the PRD. It identifies gaps, classifies them as Critical, Major, or Minor, and recommends concrete text blocks or requirement items to add.

What language is the PRD review output in?

The structured review output is always produced in Russian, following a fixed template with overall verdict, gap sections, NFR coverage, operational readiness, abuse scenarios, and recommended amendments.