sdd-spec

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates an indirect prompt injection surface by processing external proposal text and existing specifications into new requirement documents.\n
  • Ingestion points: The agent reads change proposals from sdd/{change-name}/proposal and existing specifications from openspec/specs/{domain}/spec.md.\n
  • Boundary markers: No explicit delimiters or instruction-following constraints are used to isolate the untrusted input data.\n
  • Capability inventory: The skill has the capability to write files to the project filesystem and persist architecture artifacts via internal storage modes.\n
  • Sanitization: The instructions do not define any validation or sanitization steps for the proposal content before processing.\n- [SAFE]: The skill operates within intended project boundaries, utilizing relative paths and documented persistence patterns. No malicious patterns such as credential theft, remote code execution, or persistence mechanisms were detected. The referenced shared skills and conventions are local project components.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 10:38 PM
Security Audit — agent-trust-hub — sdd-spec