wayfinder

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches established libraries (Mermaid.js, Chart.js, anime.js) and typography from well-known services including the JSDelivr CDN and Google Fonts.
  • [COMMAND_EXECUTION]: Utilizes standard system utilities (git, open, xdg-open, base64) to analyze codebase state and display generated artifacts in the browser. It also optionally invokes a vendor-provided image generation script (ai-media).
  • [CREDENTIALS_UNSAFE]: References the use of an AI_GATEWAY_API_KEY for image generation, explicitly instructing the agent to store and retrieve it from a .env file, which is a standard and safe practice for local development environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data (diffs, plans, system descriptions) to generate HTML visualizations. To mitigate risks, it includes a mandatory 'Verification Fact Sheet' workflow that requires the agent to cross-reference every claim against the actual source code before finalizing the visual output.
  • [PROMPT_INJECTION]: Instructions are focused on aesthetic consistency and visual hierarchy. No patterns were detected that attempt to bypass safety filters or override core agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — wayfinder