wayfinder

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from an external issue tracker (the "map" and its child "tickets"). Malicious instructions embedded in issue titles, bodies, or comments could influence the agent's behavior when it "loads" or "zooms" into these tickets to resolve them.
  • Ingestion points: Issue bodies, titles, and comments on the repository's issue tracker (specified in SKILL.md).
  • Capability inventory: The skill can create/modify issues, assign them to users, and invoke subagents/tools for "research" and "prototyping."
  • Boundary markers: The instructions do not define delimiters or specific warnings to ignore instructions embedded in the issue data.
  • Sanitization: There is no mention of sanitizing or validating the content retrieved from the tracker before it is used to guide the session.
  • [CREDENTIALS_UNSAFE]: The instructions for the Task ticket type suggest that the agent should record the results of its work, including "credentials location," in the resolution comment of a ticket.
  • Evidence: In SKILL.md, under "Ticket Types" (Task), it states: "The answer records what was done and any resulting facts (credentials location, new URLs, row counts) later tickets depend on."
  • While recording the "location" is less severe than recording the credential itself, documenting where secrets are stored in a collaborative issue tracker is a poor security practice that increases the risk of data exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 11:39 PM
Security Audit — agent-trust-hub — wayfinder