wayfinder

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external issue trackers, including ticket bodies and comments, to plan and resolve tasks. This creates a surface for indirect prompt injection if malicious instructions are added to the tracker by third parties. * Ingestion points: Issue tracker ticket bodies and comments referenced in SKILL.md. * Boundary markers: No delimiters or instructions to ignore embedded content are specified. * Capability inventory: The skill can create issues, wire dependencies, and launch research subagents. * Sanitization: No sanitization or validation of the external tracker content is mentioned.
  • [DATA_EXFILTRATION]: The skill's documentation for 'Task' tickets suggests recording the 'credentials location' in the resolution notes. While not suggesting storing the secrets themselves, publishing pointers to sensitive credentials in a shared repository increases the risk of data exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:48 AM
Security Audit — agent-trust-hub — wayfinder