sdd-constitution

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or dangerous operations detected. The skill is designed to generate documentation based on existing project context.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes untrusted content from the repository (README, CONTRIBUTING, code modules). Ingestion points: README, CONTRIBUTING, CLAUDE.md/AGENTS.md, and representative modules in SKILL.md. Boundary markers: Absent. Capability inventory: Writes openspec/project.md and executes openspec validate in SKILL.md. Sanitization: Absent. The risk is minimized as the output is restricted to a markdown file and validation commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 04:19 AM
Security Audit — agent-trust-hub — sdd-constitution