wayfinder

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources which could be used to influence agent behavior through embedded instructions.\n
  • Ingestion points: The skill ingests issue bodies, titles, and comments from a tracker (e.g., GitHub or local markdown) to orient its planning and decision-making process as defined in the 'Work through the map' section of SKILL.md.\n
  • Boundary markers: There are no explicit instructions or delimiters defined to help the agent distinguish between the planning metadata and potentially adversarial instructions within the user-provided issue content.\n
  • Capability inventory: The skill possesses significant capabilities, including creating and closing issues, assigning tickets to users, creating new git branches, and spawning subagents for research tasks as described in 'Invocation' section of SKILL.md.\n
  • Sanitization: The instructions do not include any patterns for sanitizing, escaping, or validating the content retrieved from the issue tracker before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 01:40 PM
Security Audit — agent-trust-hub — wayfinder