sdd-explore
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its core function of reading and processing untrusted data.
- Ingestion points: The skill reads project source code (Step 3) and retrieves project context from memory observations (Step 1).
- Boundary markers: Absent; the instructions do not specify the use of delimiters or warnings to ignore instructions that may be embedded within the source code or retrieved memory content.
- Capability inventory: The skill has the ability to save reports to a memory system (mem_save) and create a local 'exploration.md' file.
- Sanitization: Absent; the instructions do not include steps to validate, filter, or escape data retrieved from external sources before including it in generated reports or memory saves.
Audit Metadata