wayfinder
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external issue trackers, including ticket bodies and comments, to plan and resolve tasks. This creates a surface for indirect prompt injection if malicious instructions are added to the tracker by third parties. * Ingestion points: Issue tracker ticket bodies and comments referenced in SKILL.md. * Boundary markers: No delimiters or instructions to ignore embedded content are specified. * Capability inventory: The skill can create issues, wire dependencies, and launch research subagents. * Sanitization: No sanitization or validation of the external tracker content is mentioned.
- [DATA_EXFILTRATION]: The skill's documentation for 'Task' tickets suggests recording the 'credentials location' in the resolution notes. While not suggesting storing the secrets themselves, publishing pointers to sensitive credentials in a shared repository increases the risk of data exposure.
Audit Metadata