ask-navigator

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, including issue tracker comments and repository documentation, which could potentially contain malicious instructions or misleading information.
  • Ingestion points: Repository issue trackers (GitHub/GitLab comments), research documentation at docs/research/, and project context files like CONTEXT.md.
  • Boundary markers: Mandatory human-in-the-loop (HITL) checkpoints, referred to as "Captain Signatures," are required to authorize the mission destination (W1) and the decision map (W2).
  • Capability inventory: The skill can write files to the repository (e.g., .omc/wayfinder/ and docs/research/), spawn background research subagents, and execute local audit scripts.
  • Sanitization: No specific filtering or escaping mechanisms are described for the external data ingested from trackers or documentation.
  • [COMMAND_EXECUTION]: The skill executes a local Node.js script located at scripts/shipyard-audit.mjs. This script is used for auditing the repository state to identify potential issues, and its output is recorded in the task map's notes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:47 AM
Security Audit — agent-trust-hub — ask-navigator