ddd-refute
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely instructional and describes a process for evaluating claims within a specific development methodology. It does not provide the agent with any tools, commands, or access to sensitive resources.
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze external data, including project claim files (
.ddd/claims.yaml), cited sources, and documentation. While processing untrusted external content is a known vector for indirect prompt injection, this skill lacks any exploitable capabilities such as file system writes, network exfiltration, or command execution. Consequently, the risk is negligible. - Ingestion points: Reads
.ddd/claims.yamland external source text (citations). - Boundary markers: None specified.
- Capability inventory: No scripts or tools provided; the skill only contains instructions.
- Sanitization: Not applicable as no data is processed through executable tools.
Audit Metadata