ddev
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates downloading and installing add-ons from GitHub repositories using the 'ddev add-on get' command. This includes official DDEV integrations and community-maintained extensions.
- [COMMAND_EXECUTION]: The skill is designed to execute shell commands using the 'Bash' tool, routing them through the 'ddev' CLI wrapper to ensure they run within the correct project container environment.
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by reading untrusted project configuration files to determine its behavior. 1. Ingestion points: The skill reads .ddev/config.yaml and other config files to detect the project type and settings. 2. Boundary markers: None identified; it trusts the contents of the project directory. 3. Capability inventory: The skill has access to the Bash tool and is instructed to execute arbitrary wrapper commands (composer, npm, drush, etc.) as well as 'ddev exec'. 4. Sanitization: No specific sanitization of configuration values or user inputs before execution is described.
- [SAFE]: The skill's operations, including database management and service configuration, are standard for DDEV-based development and do not exhibit malicious intent. Security-sensitive features like 'ddev auth ssh' or 'ddev share' are documented as standard development workflows.
Audit Metadata