sdd-init
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the terminal to execute vendor-scoped tools, specifically
npx @ericrisco/rscfor registry management and package installation. These operations are core to the skill's purpose of repo calibration. - [EXTERNAL_DOWNLOADS]: The skill facilitates the download and installation of additional capabilities from the NPM registry via
npx @ericrisco/rsc add <skill>. These packages originate from the vendor's own scope. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest and parse untrusted data from the repository to determine build stacks and runners.
- Ingestion points: The skill reads
package.json, lockfiles,pyproject.toml,requirements.txt,go.mod,pubspec.yaml,Dockerfile, and the.github/directory as specified in theInputssection ofSKILL.md. - Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions when reading these project files.
- Capability inventory: The skill has the ability to execute shell commands via
npxand perform file writes to the02-DOCS/directory. - Sanitization: No sanitization or validation of the content read from the repository files is mentioned before the data is used to influence logic or command execution.
Audit Metadata