ddd-review

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of natural language instructions for code review based on established software engineering principles. No scripts or executable files are included with the skill.- [DATA_EXPOSURE]: There are no patterns involving access to sensitive file paths, environment variables, or hardcoded credentials. The examples provided (e.g., Order, Customer) are generic domain modeling concepts.- [REMOTE_CODE_EXECUTION]: No commands for downloading or executing external scripts (such as curl | bash) are present. The skill does not define or use any external dependencies or packages.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data (user-supplied code files or diffs).
  • Ingestion points: The skill instructions specify scanning files, diffs, or modules provided by the user (SKILL.md).
  • Boundary markers: No specific boundary markers or instructions to ignore embedded commands in the source code are defined.
  • Capability inventory: The skill does not request or utilize tools for file system writing, shell execution, or network communication.
  • Sanitization: No specific sanitization or filtering of the input code is described. Given the lack of high-privilege tool access, the risk is minimal.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 09:27 PM
Security Audit — agent-trust-hub — ddd-review