roadmap-status

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local diagnostic command using Node.js (roadmap-skill/bin/cli.js) or a global CLI tool (roadmapsmith). This behavior is consistent with the skill's stated purpose of inspecting system readiness and project status.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and summarizes JSON output from an external process (roadmapsmith doctor). While this introduces a surface where malformed tool output could influence the agent's summary, the risk is minimal as the skill does not grant additional exploitable capabilities based on this data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 10:50 PM
Security Audit — agent-trust-hub — roadmap-status