wayfinder
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external issue trackers, including ticket descriptions, map notes, and resolution comments, which represents an attack surface for indirect prompt injection where external actors could provide malicious instructions.
- Ingestion points: Data is ingested from issue maps, tickets, and notes as specified in the workflow instructions.
- Boundary markers: The skill instructs the agent to review notes before execution, but there are no technical delimiters or input validation mechanisms to separate instructions from data.
- Capability inventory: The skill allows for building artifacts (prototyping), performing web research, and executing manual tasks such as service provisioning.
- Sanitization: No automated filtering, escaping, or schema validation is mentioned for data retrieved from the issue tracker.
Audit Metadata