sdd-explore

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its core function of reading and processing untrusted data.
  • Ingestion points: The skill reads project source code (Step 3) and retrieves project context from memory observations (Step 1).
  • Boundary markers: Absent; the instructions do not specify the use of delimiters or warnings to ignore instructions that may be embedded within the source code or retrieved memory content.
  • Capability inventory: The skill has the ability to save reports to a memory system (mem_save) and create a local 'exploration.md' file.
  • Sanitization: Absent; the instructions do not include steps to validate, filter, or escape data retrieved from external sources before including it in generated reports or memory saves.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 02:23 PM