ask-navigator
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, including issue tracker comments and repository documentation, which could potentially contain malicious instructions or misleading information.
- Ingestion points: Repository issue trackers (GitHub/GitLab comments), research documentation at
docs/research/, and project context files likeCONTEXT.md. - Boundary markers: Mandatory human-in-the-loop (HITL) checkpoints, referred to as "Captain Signatures," are required to authorize the mission destination (W1) and the decision map (W2).
- Capability inventory: The skill can write files to the repository (e.g.,
.omc/wayfinder/anddocs/research/), spawn background research subagents, and execute local audit scripts. - Sanitization: No specific filtering or escaping mechanisms are described for the external data ingested from trackers or documentation.
- [COMMAND_EXECUTION]: The skill executes a local Node.js script located at
scripts/shipyard-audit.mjs. This script is used for auditing the repository state to identify potential issues, and its output is recorded in the task map's notes.
Audit Metadata