ddd-verify
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface for indirect prompt injection by processing external content.
- Ingestion points: The skill reads project source code (SKILL.md) and fetches documentation from external official URLs (references/citation-entailment.md).
- Boundary markers: There are no explicit instructions to use delimiters or ignore instructions embedded in the ingested documentation or code.
- Capability inventory: The skill possesses capabilities for modifying project files (SKILL.md) and executing shell commands for verification tests (references/test-traceability.md).
- Sanitization: No sanitization or validation of the external data is required before it influences code edits or command execution parameters.
Audit Metadata