skills/andiedie/skills/and-wayfind/Gen Agent Trust Hub

and-wayfind

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data which creates a surface for indirect prompt injection.
  • Ingestion points: The skill ingests "source evidence" from the worktree, "human reaction" from interviews, and "Research assets" containing facts from primary sources outside the current worktree (described in SKILL.md).
  • Boundary markers: The instructions use structured append-only receipts for internal state management but do not provide explicit delimiters or instructions to the agent to ignore malicious commands that might be embedded in the ingested research data or human responses.
  • Capability inventory: The skill is authorized to invoke multiple other skills (research, prototype, grilling) and perform state transitions and file writes via the and-workflow-contract.
  • Sanitization: There are no instructions for sanitizing, escaping, or validating the content of external evidence before it is interpolated into the agent's context or used to drive decision-making.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 07:30 AM
Security Audit — agent-trust-hub — and-wayfind