validate
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: Executes the roadmapsmith validate command with JSON output and project root flags to inspect roadmap evidence.- [EXTERNAL_DOWNLOADS]: Recommends installing the roadmapsmith package globally via NPM and adding a skill from the author's GitHub repository (PapiScholz/roadmapsmith) using npx.- [PROMPT_INJECTION]: Documents the attack surface for indirect prompt injection where the agent processes and summarizes output from the external validation tool. Ingestion point: JSON output from roadmapsmith validate (SKILL.md); Boundary markers: absent; Capability inventory: command execution and summarization; Sanitization: absent.
Audit Metadata