w-roadmap
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local filesystem to generate a roadmap analysis.
- Ingestion points: Reads the content of
PRODUCT.mdand the codebase (referenced inSKILL.md). - Boundary markers: Absent. The instructions do not specify the use of delimiters or warnings to prevent the agent from following instructions embedded within the source files or product documentation.
- Capability inventory: Restricted to chat output only. There are no subprocess calls, network operations, or file-write capabilities identified in the skill instructions.
- Sanitization: Absent. The skill does not describe any validation or filtering of the content read from files before it is processed by the agent.
Audit Metadata