wayfinder
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches established libraries (Mermaid.js, Chart.js, anime.js) and typography from well-known services including the JSDelivr CDN and Google Fonts.
- [COMMAND_EXECUTION]: Utilizes standard system utilities (git, open, xdg-open, base64) to analyze codebase state and display generated artifacts in the browser. It also optionally invokes a vendor-provided image generation script (
ai-media). - [CREDENTIALS_UNSAFE]: References the use of an
AI_GATEWAY_API_KEYfor image generation, explicitly instructing the agent to store and retrieve it from a.envfile, which is a standard and safe practice for local development environments. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data (diffs, plans, system descriptions) to generate HTML visualizations. To mitigate risks, it includes a mandatory 'Verification Fact Sheet' workflow that requires the agent to cross-reference every claim against the actual source code before finalizing the visual output.
- [PROMPT_INJECTION]: Instructions are focused on aesthetic consistency and visual hierarchy. No patterns were detected that attempt to bypass safety filters or override core agent behavior.
Audit Metadata