fincept-debug

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by design, as it must ingest and analyze untrusted data sources to perform debugging tasks.
  • Ingestion points: The skill processes 'Error message', 'Stack trace', and 'Reproduction steps' provided by users or external systems within various debugging workflows (SKILL.md).
  • Boundary markers: There are no specified delimiters or instructions to the agent to disregard potentially malicious commands embedded in processed logs or traces.
  • Capability inventory: The skill utilizes file system read/write operations (e.g., std::fs::read_to_string), subprocess management (e.g., execute_python_script), and network operations (e.g., requests.get) across its multi-stack workflows.
  • Sanitization: No input validation or sanitization mechanisms are defined for the data being ingested and processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — fincept-debug