maintain

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the roadmapsmith package globally via NPM and adding a skill from the author's repository PapiScholz/roadmapsmith. These are vendor-owned resources used to enable the core functionality of the skill.
  • [COMMAND_EXECUTION]: Instructs the agent to execute the roadmapsmith maintain command on the local system. This command is part of the intended workflow to generate, sync, and audit repository roadmaps.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Reads from the current project root (.) to process repository content.
  • Boundary markers: No explicit markers or instructions to ignore instructions embedded in the project files are provided in the instructions.
  • Capability inventory: The skill performs local CLI command execution via roadmapsmith and potentially accesses documentation and source code.
  • Sanitization: The instructions do not specify any validation or sanitization of the repository content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 02:24 AM
Security Audit — agent-trust-hub — maintain