wayfinder

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and act upon data retrieved from an external issue tracker, which is an untrusted data source.
  • Ingestion points: The agent is instructed to load the 'map' body (specifically the 'Destination' and 'Notes' sections) and individual ticket bodies/comments.
  • Boundary markers: The skill does not provide instructions to separate or delimit external content from internal commands, increasing the risk that retrieved text is interpreted as instructions.
  • Capability inventory: The agent can create, edit, and close issues, and is directed to dynamically invoke other skills such as /prototype or /grilling based on the content of the 'Notes' section.
  • Sanitization: No sanitization or validation of the retrieved issue content is described before the agent processes it.
  • [DATA_EXFILTRATION]: Data Exposure Risk. The skill's documentation for 'Task' tickets explicitly encourages recording potentially sensitive information in a shared environment.
  • Evidence: The instructions suggest that ticket answers should record facts such as 'credentials location' and 'new URLs', which may lead to the exposure of internal system configurations or secrets in a public or shared tracker.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 07:33 AM
Security Audit — agent-trust-hub — wayfinder