debugging-wizard

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the analysis of untrusted data sources such as stack traces and error logs, creating a potential surface for indirect prompt injection attacks.\n
  • Ingestion points: The workflow involves parsing error messages and correlating log entries, as described in SKILL.md and references/systematic-debugging.md.\n
  • Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are implemented to isolate user-supplied error data from the agent's internal instructions.\n
  • Capability inventory: The skill utilizes standard debugging and version control tools including pdb, node, dlv, and git.\n
  • Sanitization: The methodology does not include explicit sanitization, validation, or filtering of error logs before they are processed by the agent.\n- [METADATA_POISONING]: The SKILL.md frontmatter contains an author URL that does not match the provided skill author context.\n
  • Evidence: The skill metadata lists https://github.com/Jeffallan, while the skill environment identifies the author as 1git2clone.\n
  • Context: The skill documentation includes clear attribution to the original source material (obra/superpowers), suggesting that the metadata discrepancy is an artifact of forking or templating rather than a malicious attempt to deceive.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:49 PM
Security Audit — agent-trust-hub — debugging-wizard