skills/ycs77/skills/wayfinder/Gen Agent Trust Hub

wayfinder

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFECREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill instructions for 'Task' tickets in SKILL.md explicitly suggest that the agent record 'credentials location' in the resolution comments of issues. Documenting sensitive location data in an issue tracker, which may be shared or publicly accessible, creates a risk of unauthorized credential discovery.- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and act upon content from external issue trackers that could be modified by third parties.
  • Ingestion points: The agent reads content from map issues and child issues to determine the 'frontier' and next steps (SKILL.md).
  • Boundary markers: Absent. There are no instructions to use delimiters or to ignore potential instructions embedded within the ticket bodies.
  • Capability inventory: The skill can create, wire, and close issues, and invoke multiple subagents (/research, /prototype, /grilling) based on the processed data (SKILL.md).
  • Sanitization: Absent. There is no mention of filtering or validating the content retrieved from the issue tracker.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 08:10 AM
Security Audit — agent-trust-hub — wayfinder