sdd-design

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from codebase files, proposals, and specifications to generate technical designs. While it lacks explicit sanitization or boundary markers for these inputs, the skill includes a mandatory security review step (Step 2a) that forces the agent to evaluate threat vectors like shell command injection and path traversal when applicable to the design. This design-time security check acts as a significant mitigating control.
  • Ingestion points: codebase files, sdd/{change-name}/proposal, and sdd/{change-name}/spec (SKILL.md).
  • Boundary markers: None specified in instructions.
  • Capability inventory: File system writes (design.md) and persistent storage via the Engram system.
  • Sanitization: None specified for ingested technical content.
  • [SAFE]: The skill does not contain any obfuscated code, unauthorized network calls, or credential harvesting patterns. All file operations and persistence mechanisms are within the scope of its stated architectural design purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 03:16 PM
Security Audit — agent-trust-hub — sdd-design