skills/ericrisco/rsc-harness/sdd-init/Gen Agent Trust Hub

sdd-init

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the terminal to execute vendor-scoped tools, specifically npx @ericrisco/rsc for registry management and package installation. These operations are core to the skill's purpose of repo calibration.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download and installation of additional capabilities from the NPM registry via npx @ericrisco/rsc add <skill>. These packages originate from the vendor's own scope.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest and parse untrusted data from the repository to determine build stacks and runners.
  • Ingestion points: The skill reads package.json, lockfiles, pyproject.toml, requirements.txt, go.mod, pubspec.yaml, Dockerfile, and the .github/ directory as specified in the Inputs section of SKILL.md.
  • Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions when reading these project files.
  • Capability inventory: The skill has the ability to execute shell commands via npx and perform file writes to the 02-DOCS/ directory.
  • Sanitization: No sanitization or validation of the content read from the repository files is mentioned before the data is used to influence logic or command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:56 AM
Security Audit — agent-trust-hub — sdd-init