systematic-debugging
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The documentation in
SKILL.mdprovides diagnostic command examples that access sensitive system state, including environment variables (e.g.,IDENTITY) and macOS keychain data via thesecurityutility. These examples demonstrate how to expose credentials and identity secrets during the investigation of build and signing issues. - [COMMAND_EXECUTION]: The utility script
find-polluter.shperforms local command execution by runningnpm teston files identified through user-provided patterns. This is a standard debugging technique but represents a controlled execution of local code. - [DATA_EXFILTRATION]: The debugging methodology encourages the agent to implement diagnostic logging at component boundaries to trace data flow. This practice can lead to the unintended exposure of sensitive operational data, such as authentication tokens, secrets, or personally identifiable information (PII), if the data being logged is not properly sanitized.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it instructs the agent to ingest and analyze untrusted external content, such as error messages and stack traces, to guide its diagnostic and fix-implementation logic.
- Ingestion points: Error messages, stack traces, and log files parsed during Phase 1.
- Boundary markers: No explicit markers or instructions are provided to isolate or neutralize potential commands embedded in the ingested logs or error data.
- Capability inventory: File system access, local code execution via
npm test, and diagnostic shell command execution (e.g.,codesign,security). - Sanitization: The process does not mandate any validation or sanitization of the input data before analysis.
Audit Metadata