wayfinder
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates an indirect prompt injection attack surface by processing untrusted data from an external issue tracker.
- Ingestion points: The agent is instructed to 'Load the map' and 'fetch the full body' of tickets from an external source (SKILL.md).
- Capability inventory: The agent can create or modify issues and invoke secondary skills like '/prototype' and '/grilling' (SKILL.md).
- Boundary markers: The instructions lack delimiters or 'ignore' instructions for data retrieved from the tracker.
- Sanitization: No validation or sanitization process for external inputs is defined.
Audit Metadata