sdd
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill relies on project-local configuration and profile files to determine its operational parameters, accompaniment levels, and autonomous behavior.
- Ingestion points: The skill ingests data from
02-DOCS/wiki/harness/user-profile.mdto set the 'accompaniment dial' and from02-DOCS/wiki/sdd/config.yamlto configure 'Autopilot' mode and model routing. - Boundary markers: There are no explicit delimiters or 'ignore embedded instructions' markers defined for the data read from these configuration files.
- Capability inventory: The skill has the ability to write multiple artifacts to the
02-DOCS/wiki/sdd/directory, invoke sibling phase skills (e.g.,../specify/SKILL.md), delegate tasks via theTasktool, and issue commands to the assistant host. - Sanitization: The skill instructions do not specify any validation, escaping, or filtering for the external configuration content prior to use in execution logic.
- [COMMAND_EXECUTION]: The skill directs the agent to issue platform-specific control commands, such as
/model <name>, to dynamically switch the active language model for the session or for specific sub-tasks. This capability is used to optimize cost and reasoning quality across different development phases. - [DYNAMIC_EXECUTION]: The skill implements an 'Autopilot' mode which, upon initial user consent, enables the agent to execute a multi-step chain of development phases (from specification through to verification and review) without requiring intermediate human approval between steps. This represents a high degree of agent autonomy in the development process.
Audit Metadata