w-roadmap

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local filesystem to generate a roadmap analysis.
  • Ingestion points: Reads the content of PRODUCT.md and the codebase (referenced in SKILL.md).
  • Boundary markers: Absent. The instructions do not specify the use of delimiters or warnings to prevent the agent from following instructions embedded within the source files or product documentation.
  • Capability inventory: Restricted to chat output only. There are no subprocess calls, network operations, or file-write capabilities identified in the skill instructions.
  • Sanitization: Absent. The skill does not describe any validation or filtering of the content read from files before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 12:07 AM
Security Audit — agent-trust-hub — w-roadmap