wayfinder
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from a repository's issue tracker, creating a surface for instructions embedded in issue bodies to influence agent behavior.
- Ingestion points: The agent reads the 'map' issue body, child ticket questions, and the 'Decisions so far' index from the external tracker.
- Boundary markers: The instructions lack specific requirements for delimiters or 'ignore embedded instructions' warnings when parsing content from the tracker.
- Capability inventory: The skill possesses the ability to create, modify, and close issues, and it can spawn subagents to perform research and prototyping using a 'Skill tool'.
- Sanitization: There are no documented procedures for sanitizing or validating the text content retrieved from the issue tracker before it is used to orient the session.
Audit Metadata