sdd-design

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from the codebase to inform its design decisions.
  • Ingestion points: The skill reads the project's source code, entry points, and module structures in Step 1.
  • Boundary markers: The instructions do not define delimiters or warnings to ignore instructions embedded within the source code comments or strings.
  • Capability inventory: The skill has the authority to write to the file system to create design.md files.
  • Sanitization: There is no evidence of filtering or sanitization of the content read from the codebase before it is used to generate the design document.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 12:23 AM
Security Audit — agent-trust-hub — sdd-design