ep-navigator

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOW
Full Analysis
  • [PROMPT_INJECTION] (SAFE): No override or bypass markers were detected. The skill instructions are purely task-oriented for project navigation.
  • [DATA_EXFILTRATION] (SAFE): The skill uses tools to read project source and documentation files. No access to system secrets or network capabilities were found.
  • [INDIRECT_PROMPT_INJECTION] (LOW):
  • Ingestion points: Reads external memory files (EP{编号}.md) and user-provided EP identifiers.
  • Boundary markers: None explicitly defined.
  • Capability inventory: Uses mcp__serena__read_memory, Read, and Grep. These are strictly read-only tools.
  • Sanitization: None present.
  • Risk: Although it processes external data, the lack of write or execute capabilities limits the potential for exploitation.
  • [REMOTE_CODE_EXECUTION] (SAFE): No remote script downloads or dynamic execution patterns were identified.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 08:16 PM