sdd-archive
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from delta specifications and merges them into main specification files without sanitization or boundary markers.\n
- Ingestion points: Reads delta specifications from
openspec/changes/{change-name}/specs/as described in Step 2, and Engram artifacts (proposal, design, tasks) in Step 1.\n - Boundary markers: None present to delimit or isolate external content during the merge process into the source of truth specs.\n
- Capability inventory: The skill performs file read, write, and directory move operations on the local filesystem (
openspec/specs/).\n - Sanitization: No markdown sanitization or instruction filtering is applied to the content before it is merged into the project's source of truth documents.
Audit Metadata