lcs-wayfinder
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user input and reads from the codebase to generate planning artifacts. While it lacks explicit boundary markers or sanitization for external content, this is inherent to its primary function as a planning tool for developers.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill interacts with local state files and codebase paths (e.g., .lcs/state.md and shared contract files). These operations are restricted to the local file system for the purpose of maintaining project state and do not involve data exfiltration or external network access.
Audit Metadata