check-wayfinder-maps

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by reading map bodies and tracking tickets from external GitHub repositories.
  • Ingestion points: The skill reads the body of every open map and related tracker issues during the bulk survey phase (SKILL.md, Process Step 3).
  • Boundary markers: No explicit delimiters or instructions are provided to the model to ignore potential instructions embedded within the GitHub issues.
  • Capability inventory: The skill is explicitly defined as read-only ("This skill never writes. No claims, no comments, no closes, no map edits"). It does not execute code, perform network writes, or modify the filesystem based on the ingested data.
  • Sanitization: No specific sanitization or filtering of the external ticket content is mentioned.
  • Risk assessment: While the ingestion surface exists, the risk is negligible because the output is formatted as a report (table and prompts) for a human user to review, and the skill lacks the capabilities to perform autonomous actions or system modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 01:30 PM
Security Audit — agent-trust-hub — check-wayfinder-maps