wayfinder
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from an external issue tracker, creating a surface for indirect instructions to influence agent behavior.\n
- Ingestion points: The agent loads the map body and ticket content from the issue tracker as described in SKILL.md.\n
- Capability inventory: The skill allows the agent to create and close issues, post comments, and invoke other functional skills like /prototype or /grilling.\n
- Boundary markers: There are no specific instructions or delimiters provided to separate data fetched from the tracker from system instructions.\n
- Sanitization: The skill does not define any sanitization or validation logic for the content retrieved from the external tracker.\n- [COMMAND_EXECUTION]: The skill facilitates the execution of manual tasks and the creation of artifacts through the /prototype skill based on ticket descriptions.\n- [DYNAMIC_EXECUTION]: The Prototype ticket type enables the generation of code (UI or logic) via the /prototype skill, which introduces the risk of executing untrusted logic if the source ticket content is compromised.
Audit Metadata