wayfinder

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill manages project state by interacting with issue tracker APIs to create, label, and close tickets, and performs Git operations such as creating dedicated research branches for subagents.\n- [INDIRECT_PROMPT_INJECTION]: The skill reads content from external issue trackers, which represents a surface for instructions from untrusted sources to influence agent behavior.\n
  • Ingestion points: Issue tracker bodies (map and child tickets) and resolution comments (SKILL.md).\n
  • Boundary markers: None specified in the skill instructions.\n
  • Capability inventory: Git operations, Issue Tracker API calls (create, close, assign), tool execution, and subagent spawning.\n
  • Sanitization: None described in the skill logic.\n- [DYNAMIC_EXECUTION]: The skill orchestrates task resolution by spawning subagents and calling specialized tools such as 'research', 'prototype', and 'grilling'.\n- [EXTERNAL_DOWNLOADS]: Research subagents are instructed to fetch and analyze information from third-party APIs and external documentation to inform the map's decisions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:23 PM
Security Audit — agent-trust-hub — wayfinder