roadmap-status
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local diagnostic command using Node.js (
roadmap-skill/bin/cli.js) or a global CLI tool (roadmapsmith). This behavior is consistent with the skill's stated purpose of inspecting system readiness and project status. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and summarizes JSON output from an external process (
roadmapsmith doctor). While this introduces a surface where malformed tool output could influence the agent's summary, the risk is minimal as the skill does not grant additional exploitable capabilities based on this data.
Audit Metadata