track-roadmap

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill defines legitimate project management workflows with no evidence of malicious intent, obfuscation, or unauthorized access.\n- [COMMAND_EXECUTION]: The skill performs standard file operations (reading/writing ROADMAP.md and session files) and directory scanning. These actions are within the expected scope of a roadmap tool.\n- [PROMPT_INJECTION]: While the codebase scan feature ingests external content from project files and comments, which is a potential surface for indirect prompt injection, the skill mitigates this by requiring the agent to summarize findings and obtain user confirmation for all changes.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:09 PM
Security Audit — agent-trust-hub — track-roadmap