skills/romiluz13/ddd/ddd-audit/Gen Agent Trust Hub

ddd-audit

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes existing codebase symbols and documentation (ADRs, READMEs, wiki). While this is an ingestion surface for untrusted data, the instructions are focused on structural analysis and documentation matching. The risk is minimized by the analytical nature of the task and is considered a standard operational surface.
  • [REMOTE_CODE_EXECUTION]: No remote code execution or external package installation patterns were identified in the skill instructions or reference files.
  • [DATA_EXFILTRATION]: The skill operates locally on the codebase to generate reports. There are no network operations (curl, wget) or commands that transmit data to external domains.
  • [CREDENTIALS_UNSAFE]: The skill does not contain or request hardcoded secrets. It explicitly mentions identifying 'Security boundaries' and 'Auth checks' as part of the audit process, which is a standard security practice.
  • [COMMAND_EXECUTION]: The skill describes a conceptual workflow (Scan, Extract, Match, Flag) without providing executable shell scripts or dangerous system commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 03:01 PM
Security Audit — agent-trust-hub — ddd-audit