qa-map
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No prompt injection or safety bypass instructions were detected in the skill instructions.
- [SAFE]: File access is restricted to reading the codebase and upstream artifacts for discovery purposes and writing the resulting maps to the
.context/directory. - [SAFE]: Command execution is limited to standard development tools like
git difffor incremental mapping, which is appropriate for the skill's stated purpose. - [SAFE]: The skill does not perform any network operations to non-whitelisted or suspicious external domains.
- [SAFE]: Although the skill processes untrusted codebase data (potential Indirect Prompt Injection surface), its operations are limited to structural mapping rather than executing the content of the files it analyzes.
Audit Metadata