fincept-debug
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by design, as it must ingest and analyze untrusted data sources to perform debugging tasks.
- Ingestion points: The skill processes 'Error message', 'Stack trace', and 'Reproduction steps' provided by users or external systems within various debugging workflows (SKILL.md).
- Boundary markers: There are no specified delimiters or instructions to the agent to disregard potentially malicious commands embedded in processed logs or traces.
- Capability inventory: The skill utilizes file system read/write operations (e.g.,
std::fs::read_to_string), subprocess management (e.g.,execute_python_script), and network operations (e.g.,requests.get) across its multi-stack workflows. - Sanitization: No input validation or sanitization mechanisms are defined for the data being ingested and processed.
Audit Metadata