diagnosing-bugs
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill implements a security-first approach to data handling by explicitly instructing the agent to redact all secrets and credentials, replacing them with
<REDACTED>, before displaying command outputs or artifacts. It also advises building loops against environment variables to keep credentials out of the captured logs. - [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to run a local template script (scripts/hitl-loop.template.sh). This script is used to facilitate human-in-the-loop (HITL) debugging, allowing the agent to prompt the user for manual steps and capture observations. The script is designed for interactive input and does not perform automated remote execution. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and process external data such as error messages, log dumps, and user-provided artifacts during the debugging process.
- Ingestion points: The
scripts/hitl-loop.template.shscript captures free-form user input (e.g.,ERROR_MSG) which is then passed back to the agent context. - Boundary markers: While the prompt instructions suggest quoting lines and redacting content, the interactive script itself does not enforce strict delimiters or markers to isolate the user input from the agent's instructions.
- Capability inventory: The skill has access to powerful tools including
Bash,Write, andEdit, which could be targeted by instructions embedded within malicious log files or error messages. - Sanitization: There is no automated sanitization or filtering of the captured output within the provided shell script template.
Audit Metadata