read-the-map
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub issue bodies, specifically fields like
Notesandexecution overrides. It explicitly instructs the agent to prioritize these external instructions over its own logic ("A map's own Notes outrank your inference"). This creates a vulnerability where an attacker with write access to the repository's issues could influence the agent's assessment or subsequent actions. - Ingestion points: GitHub issue bodies and titles are read from the repository.
- Boundary markers: None identified; the instructions do not require the agent to delimit or treat the external content as untrusted.
- Capability inventory: Although the skill itself is read-only, it generates the primary input for other high-capability tools such as
/wayfinder,/decisions-to-specs, and/specs-to-tickets. - Sanitization: No sanitization, escaping, or validation of the ingested issue content is specified in the skill instructions.
Audit Metadata