diagnose
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions direct the agent to utilize various system-level commands to inspect the environment and reproduce bugs. Examples include monitoring processes (
ps), checking service statuses (systemctl), performing network probes (curl), and using version control tools for bisection (git bisect).\n- [DYNAMIC_EXECUTION]: The skill methodology requires the agent to generate and execute functional code for the purpose of diagnosis. This includes creating throwaway test harnesses, integration scripts, and utilizing templates for human-in-the-loop reproduction loops (as seen inscripts/hitl-loop.template.sh).\n- [INDIRECT_PROMPT_INJECTION]: As a debugging tool, the skill is designed to ingest and process untrusted external data (bug reports, log files, network traces). This creates an attack surface for indirect prompt injection, particularly when the agent is granted capabilities like file writing and command execution to resolve issues. The ingestion points include log files and traces, while the capability inventory includes file-writing and subprocess execution; boundary markers and sanitization are not explicitly defined.
Audit Metadata