sdd-verify
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill is designed to automatically detect and run build and test commands found in configuration files such as
package.json,pyproject.toml, oropenspec/config.yaml. This execution is the intended primary function for providing behavioral evidence of code correctness.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it ingests various local project files (specification scenarios, design documents, and task lists) to guide its logic and generate compliance reports.\n - Ingestion points: The skill reads contents from
specs/,design.md,tasks.md, andopenspec/config.yaml.\n - Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following instructions embedded within these source files.\n
- Capability inventory: The skill has high-privilege shell access to execute build and test commands.\n
- Sanitization: No validation or sanitization steps are documented before processing the file content or incorporating it into the verification summary.
Audit Metadata