wayfinder

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No security issues detected. The skill instructions describe a legitimate workflow for project planning and task management through issue trackers.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it processes untrusted data from an external issue tracker, such as ticket descriptions and comments. This surface is necessary for the skill's primary function.
  • Ingestion points: Issue tracker bodies, comments, and labels (SKILL.md).
  • Boundary markers: None explicitly defined to isolate external user content.
  • Capability inventory: The skill can create and edit issues, wire blocking relationships, create Git branches, and invoke subagents for research tasks (SKILL.md).
  • Sanitization: The instructions do not specify any validation or sanitization for ingested tracker data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:19 PM
Security Audit — agent-trust-hub — wayfinder