debugging-wizard
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external, untrusted data including error messages, stack traces, and log entries during the reproduction and isolation phases.
- Ingestion points: Data enters the agent's context through triggers like 'error', 'traceback', and 'log analysis' as described in
SKILL.mdandreferences/systematic-debugging.md. - Boundary markers: The instructions lack explicit delimiters or safety warnings for the agent to ignore potentially malicious instructions embedded within the processed logs or error strings.
- Capability inventory: The skill environment permits the execution of powerful command-line tools (pdb, node, delve), which could be targets for manipulation via injected instructions.
- Sanitization: No logic is present to sanitize or escape data extracted from external logs before it is processed by the agent.
- [DYNAMIC_EXECUTION]: The skill provides the agent with instructions and templates for executing powerful debugging and version control tools.
- Evidence:
SKILL.mdandreferences/debugging-tools.mdinclude commands for launching language-specific debuggers such aspython -m pdb,node --inspect-brk, anddlv debug, as well as performing regression hunting withgit bisect. While intended for legitimate debugging, these tools grant the agent significant control over the local execution environment. - [METADATA_POISONING]: There is an inconsistency between the skill's internal author metadata (
https://github.com/Jeffallan) and the provided vendor context. - Evidence: The
SKILL.mdfile identifies the author ashttps://github.com/Jeffallan, which differs from the provided context. While this may be a fork, it represents a metadata discrepancy in the skill's identity.
Audit Metadata