indexion-sdd

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx to download and execute the cc-sdd package directly from the public npm registry (npx cc-sdd@latest --yes). This package does not originate from a recognized trusted organization or the specified vendor's verified resource list, posing a supply chain risk. The use of the --yes flag bypasses confirmation, executing the package immediately upon download.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted external data, such as RFC documents and ISO standards, which are processed and used to drive AI-led implementation tasks.\n
  • Ingestion points: Specification documents (rfc_document.md, spec.pdf) are read by the indexion tool and refined into requirements that are subsequently processed by the codex agent.\n
  • Boundary markers: No explicit delimiters or instruction-isolation markers are documented for the prompts that incorporate these external requirements.\n
  • Capability inventory: The skill uses codex exec with the --full-auto flag, granting the agent autonomy to execute shell commands, perform git commits, and modify project files based on the specification content.\n
  • Sanitization: There is no evidence of sanitization or safety filtering for the content extracted from the external documents before it is used to influence the agent's behavior.\n- [DYNAMIC_EXECUTION]: The skill dynamically constructs Markdown instruction files (impl-phase-a.md, impl-phase-b.md) at runtime using shell redirection and sed templates. These generated files are then passed as direct instructions to a sub-agent via codex exec, creating a complex execution model where the primary skill generates and runs arbitrary sub-prompts.\n- [COMMAND_EXECUTION]: The skill employs a wide range of powerful shell commands, including process monitoring and termination (ps, kill, lsof), file system manipulation, and extensive git operations. These capabilities increase the potential impact of any successful prompt injection attack.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 01:04 AM
Security Audit — agent-trust-hub — indexion-sdd