create-roadmap

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs standard file-based documentation processing within the local project structure. It reads documentation files and writes a markdown roadmap without any external network calls or dangerous system modifications.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from product documents (PRDs, metrics frameworks) located in .chalk/docs/product/. While these files could contain malicious instructions, the skill's capabilities are limited to reading text and writing markdown files, which mitigates the risk of harm. No sanitization or boundary markers are explicitly defined for these ingestion points.
  • [DATA_EXPOSURE]: File access is constrained to specific project documentation paths. There is no evidence of the skill attempting to access sensitive environment variables, SSH keys, or cloud credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 06:58 AM
Security Audit — agent-trust-hub — create-roadmap