dd-product-recommender

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists solely of markdown instructions for the AI agent and does not include any executable scripts, binaries, or hidden code.
  • [SAFE]: Behavioral guardrails are explicitly defined to prevent the agent from performing dangerous actions such as modifying files, installing software, or executing shell commands.
  • [PROMPT_INJECTION]: The skill analyzes user-provided manifest files to detect technology stacks. The potential risk of indirect injection via malicious file content is mitigated by the skill's strict output schema and lack of operational capabilities. Ingestion points: Reads local project files like package.json, go.mod, and requirements.txt. Boundary markers: Includes specific instructions to only output recommendations and rationals within a 3-product cap. Capability inventory: Uses file-read for analysis and AskUserQuestion for user interaction; no system-modifying capabilities are present. Sanitization: Operates by mapping detected text signals to a static internal product catalog.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 05:43 AM
Security Audit — agent-trust-hub — dd-product-recommender