materialize-roadmap-threads

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes data from a roadmap.md file to drive the creation of new files and folders. This represents a surface for indirect prompt injection where malicious instructions embedded in a brief could influence the materialization process.
  • Ingestion points: Reads content from roadmap.md located within docs/threads/ directory structures.
  • Boundary markers: Employs a preflight validation step to check for well-formed headings and required fields before execution.
  • Capability inventory: Utilizes /allocate-thread for directory and file creation, modifies roadmap.md, and calls /emit-pending-decisions for error handling.
  • Sanitization: Validates brief structure and identities but does not explicitly filter content for embedded instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 08:08 AM
Security Audit — agent-trust-hub — materialize-roadmap-threads