sdd-propose

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data sources which represents a potential injection surface, though it is standard for its intended use case.\n
  • Ingestion points: Reads from project-local files at docs/sdd/{change-name}/explore.md and retrieves information via mem_search.\n
  • Boundary markers: The instructions do not explicitly define delimiters for external content within this wrapper file.\n
  • Capability inventory: The skill has the ability to perform disk Write operations to project directories and save data to long-term memory via mem_save.\n
  • Sanitization: No explicit content filtering or sanitization steps are documented for the ingested data.\n- [SAFE]: The skill's architecture relies on local file resolution and standard development tools, following the principle of least privilege by scoping file operations to the docs/sdd/ directory.\n- [SAFE]: No evidence of obfuscation, remote code downloads, or unauthorized network communication was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 05:42 AM
Security Audit — agent-trust-hub — sdd-propose