gds-prd

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses uv run to execute a local Python script resolve_customization.py during activation. This is a standard practice for resolving configuration in this platform environment.
  • [COMMAND_EXECUTION]: The validation process invokes platform openers (open, xdg-open, start "") to display the generated HTML validation report to the user. This is a user-facing UI convenience and not a security risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied inputs and GDDs. It employs 'Extract, don't ingest' patterns using subagents to mitigate context poisoning and uses explicit boundary markers and reconciliation steps in the Finalize workflow.
  • [EXTERNAL_DOWNLOADS]: The customize.toml and SKILL.md mention external tools and handoffs (e.g., Confluence). These are registry-based and user-configured via the workflow, rather than arbitrary remote code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 08:00 PM
Security Audit — agent-trust-hub — gds-prd