sdd-propose
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data sources which represents a potential injection surface, though it is standard for its intended use case.\n
- Ingestion points: Reads from project-local files at
docs/sdd/{change-name}/explore.mdand retrieves information viamem_search.\n - Boundary markers: The instructions do not explicitly define delimiters for external content within this wrapper file.\n
- Capability inventory: The skill has the ability to perform disk
Writeoperations to project directories and save data to long-term memory viamem_save.\n - Sanitization: No explicit content filtering or sanitization steps are documented for the ingested data.\n- [SAFE]: The skill's architecture relies on local file resolution and standard development tools, following the principle of least privilege by scoping file operations to the
docs/sdd/directory.\n- [SAFE]: No evidence of obfuscation, remote code downloads, or unauthorized network communication was found.
Audit Metadata