sdd-spec
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill demonstrates an indirect prompt injection surface by processing external proposal text and existing specifications into new requirement documents.\n
- Ingestion points: The agent reads change proposals from
sdd/{change-name}/proposaland existing specifications fromopenspec/specs/{domain}/spec.md.\n - Boundary markers: No explicit delimiters or instruction-following constraints are used to isolate the untrusted input data.\n
- Capability inventory: The skill has the capability to write files to the project filesystem and persist architecture artifacts via internal storage modes.\n
- Sanitization: The instructions do not define any validation or sanitization steps for the proposal content before processing.\n- [SAFE]: The skill operates within intended project boundaries, utilizing relative paths and documented persistence patterns. No malicious patterns such as credential theft, remote code execution, or persistence mechanisms were detected. The referenced shared skills and conventions are local project components.
Audit Metadata