indexion-sdd
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes
npxto download and execute thecc-sddpackage directly from the public npm registry (npx cc-sdd@latest --yes). This package does not originate from a recognized trusted organization or the specified vendor's verified resource list, posing a supply chain risk. The use of the--yesflag bypasses confirmation, executing the package immediately upon download.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted external data, such as RFC documents and ISO standards, which are processed and used to drive AI-led implementation tasks.\n - Ingestion points: Specification documents (
rfc_document.md,spec.pdf) are read by theindexiontool and refined into requirements that are subsequently processed by thecodexagent.\n - Boundary markers: No explicit delimiters or instruction-isolation markers are documented for the prompts that incorporate these external requirements.\n
- Capability inventory: The skill uses
codex execwith the--full-autoflag, granting the agent autonomy to execute shell commands, perform git commits, and modify project files based on the specification content.\n - Sanitization: There is no evidence of sanitization or safety filtering for the content extracted from the external documents before it is used to influence the agent's behavior.\n- [DYNAMIC_EXECUTION]: The skill dynamically constructs Markdown instruction files (
impl-phase-a.md,impl-phase-b.md) at runtime using shell redirection andsedtemplates. These generated files are then passed as direct instructions to a sub-agent viacodex exec, creating a complex execution model where the primary skill generates and runs arbitrary sub-prompts.\n- [COMMAND_EXECUTION]: The skill employs a wide range of powerful shell commands, including process monitoring and termination (ps,kill,lsof), file system manipulation, and extensive git operations. These capabilities increase the potential impact of any successful prompt injection attack.
Audit Metadata