project-roadmap

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from the project's CLAUDE.md file to determine roadmap content.\n
  • Ingestion points: CLAUDE.md file in the project root.\n
  • Boundary markers: The skill does not use explicit delimiters when reading from the source file.\n
  • Capability inventory: The skill's capabilities are restricted to generating documentation files (ROADMAP.md and HTML) using the present_files tool. It does not perform shell command execution or network operations.\n
  • Sanitization: No specific sanitization or filtering of the input data is described before it is used in the output templates.\n- [EXTERNAL_DOWNLOADS]: The generated visual roadmap references fonts from Google Fonts (fonts.googleapis.com), a well-known and trusted service provider.\n- [SAFE]: The skill references several Laravel packages (e.g., cleaniquecoders/laravel-running-number) which are part of the author's established ecosystem and are used for instructional purposes in the generated roadmap.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 11:24 AM
Security Audit — agent-trust-hub — project-roadmap