sdd-draft-tasks

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of prompt injection, jailbreak attempts, or instructions to bypass safety guardrails was found. The skill follows a structured 'interview' format based on a predefined question bank.
  • [DATA_EXFILTRATION]: The skill does not perform network operations (e.g., curl, wget) and does not access sensitive system files or credentials. It only reads specific project planning assets and approved design files.
  • [REMOTE_CODE_EXECUTION]: The instructions include a 'Hard Rule' for 'plan-only' access, which strictly forbids code edits, builds, installs, or any execution-related actions.
  • [COMMAND_EXECUTION]: There are no shell commands or administrative actions requested. The output is restricted to generating Markdown documentation.
  • [PROMPT_INJECTION]: While the skill ingests external specification and design documents (Indirect Prompt Injection surface), the risk is negligible because the skill operates in a read-only context with no execution capabilities, and the generated output is reviewed by the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 05:26 PM
Security Audit — agent-trust-hub — sdd-draft-tasks