sdd-explore

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from the local codebase and configuration files (such as openspec/config.yaml and sdd-init/). This creates a surface for indirect prompt injection if the files being analyzed contain malicious instructions disguised as comments, documentation, or data.
  • Ingestion points: The agent reads project files during 'Step 3: Investigate the Codebase' and retrieves context from sdd-init/ and openspec/ directories.
  • Boundary markers: No explicit boundary markers or 'ignore' instructions for processed data are defined in this skill.
  • Capability inventory: The agent has the capability to read project files and write a new exploration.md file to the filesystem.
  • Sanitization: No sanitization or filtering logic for the ingested content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 03:17 PM
Security Audit — agent-trust-hub — sdd-explore