skills/akillness/jeo-skills/wayfinder/Gen Agent Trust Hub

wayfinder

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external issue trackers or local markdown files, which are potentially untrusted data sources.
  • Ingestion points: The skill instructions specify fetching map bodies and ticket questions from an issue tracker (SKILL.md, 'The Map' and 'Work through the map' sections).
  • Boundary markers: The skill does not define specific delimiters or instructions to treat data from the issue tracker as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill has access to powerful tools including Bash, Write, Edit, and Read, which could be exploited if malicious content in a ticket is misinterpreted as an instruction.
  • Sanitization: There are no explicit validation or sanitization routines described for content retrieved from the tracker.
  • [COMMAND_EXECUTION]: The skill instructions utilize the Bash tool to perform tracker-specific operations and to drive research subagents as part of its core planning logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 02:15 PM
Security Audit — agent-trust-hub — wayfinder