ddd-refiner
Pass
Audited by Gen Agent Trust Hub on May 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to assist in the architectural documentation of a project through an interactive interview process. All actions, including reading repository metadata and writing configuration files, are within the expected scope of a development assistant tool.
- [DATA_EXPOSURE]: The skill accesses repository content (e.g., folder structures, code patterns) and project configuration files (
.lattice/config.yaml). This data is used exclusively to inform the conversation with the user and is not transmitted to any external or third-party services. - [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface as it reads existing principles documents and repository code. However, the capability is limited to generating documentation and updating local configuration settings. Standard LLM safety filters and the nature of the output (markdown) mitigate this risk to a safe level.
- [COMMAND_EXECUTION]: There are no shell commands, scripts, or dynamic context injections (
!command) present in the skill instructions or associated assets.
Audit Metadata