visual-wayfinder
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill architecture enforces a strict 'static boundary' between generated UI and system actions, as described in SKILL.md and references/architecture.md. This prevents the model from performing unauthorized tracker writes or navigation.
- [SAFE]: The skill uses an allowlisted component catalog (references/json-render-spec.md) and rejects arbitrary HTML, JavaScript, or tool names. This effectively mitigates risks of remote code execution through the rendering layer.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection via the ingestion of Wayfinder tickets. Evidence chain: 1) Ingestion points: Wayfinder decision tickets and tracker metadata (SKILL.md). 2) Boundary markers: The use of host-owned shells and renderer-independent answer envelopes (references/answer-envelope.md). 3) Capability inventory: The skill is restricted to generating JSON specs and cannot execute shell commands or write files directly. 4) Sanitization: Mandatory schema validation and sanitization of text inputs.
- [SAFE]: All identified dependencies (Wayfinder, json-render-core) are internal platform resources. No external network downloads or untrusted code patterns were detected.
Audit Metadata