hsdd-milestone
Pass
Audited by Gen Agent Trust Hub on Jul 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill only interacts with local files in the 'hsdd/' directory for reading specifications and writing reports, posing no risk of exfiltration.
- [SAFE]: No network commands, external dependencies, or remote code execution patterns were found.
- [SAFE]: The skill does not access sensitive system paths, credentials, or environment variables.
- [SAFE]: While the skill ingests content from project files (a potential indirect injection surface), it is considered safe because it lacks dangerous capabilities like network access or shell execution. Ingestion points: hsdd/spec/ directory. Boundary markers: Absent. Capability inventory: File write to hsdd/management/. Sanitization: Absent.
Audit Metadata