and-wayfind
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a structured workflow for resolving uncertainty, using a destination-driven map and discrete investigation records. Its operations are purely procedural and do not contain malicious instructions.
- [SAFE]: External resource interaction is conducted through well-defined contracts (e.g.,
and-backend-contract,and-interview-contract) and specific tools likeresearchandprototype. These tools are integrated into the workflow suite and do not represent unauthorized remote code execution. - [SAFE]: The skill maintains project state using local configuration (
.and/config.yml) and links to external gists for decision records. These are standard practices for development-oriented agents and utilize well-known services for storage. - [SAFE]: No obfuscation, such as Base64-encoded strings, zero-width characters, or hidden URLs, was found in the skill content.
- [SAFE]: Security boundaries are explicitly defined, such as requiring dedicated investigation branches for prototype/research work and restricting delivery actions (e.g., costs, secrets, permissions) to human actors.
Audit Metadata