diagnosing-bugs

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements a security-first approach to data handling by explicitly instructing the agent to redact all secrets and credentials, replacing them with <REDACTED>, before displaying command outputs or artifacts. It also advises building loops against environment variables to keep credentials out of the captured logs.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to run a local template script (scripts/hitl-loop.template.sh). This script is used to facilitate human-in-the-loop (HITL) debugging, allowing the agent to prompt the user for manual steps and capture observations. The script is designed for interactive input and does not perform automated remote execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and process external data such as error messages, log dumps, and user-provided artifacts during the debugging process.
  • Ingestion points: The scripts/hitl-loop.template.sh script captures free-form user input (e.g., ERROR_MSG) which is then passed back to the agent context.
  • Boundary markers: While the prompt instructions suggest quoting lines and redacting content, the interactive script itself does not enforce strict delimiters or markers to isolate the user input from the agent's instructions.
  • Capability inventory: The skill has access to powerful tools including Bash, Write, and Edit, which could be targeted by instructions embedded within malicious log files or error messages.
  • Sanitization: There is no automated sanitization or filtering of the captured output within the provided shell script template.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 02:14 PM
Security Audit — agent-trust-hub — diagnosing-bugs