systematic-debugging

Fail

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The file phases/fault-injection.md includes instructions for the agent to execute system-level commands using sudo (e.g., sudo tc qdisc add dev eth0 root netem delay 500ms 100ms). This encourages the use of elevated privileges for network fault injection, creating a security risk if the environment is not strictly isolated.
  • [COMMAND_EXECUTION]: The provided shell utility find-polluter.sh accepts a user-specified command (TEST_CMD) and executes it using bash -c inside a timeout wrapper. This pattern allows for arbitrary command execution on the host machine if the agent passes an unsanitized string derived from user input.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data, including application logs, test outputs, and bug reports. The workflow documentation lacks boundary markers or explicit instructions to ignore embedded commands in this data, allowing for an attack where a malicious log entry or bug report could influence the agent to execute dangerous commands using the skill's built-in tools.
  • [COMMAND_EXECUTION]: The phases/fault-injection.md file suggests using commands like fallocate and stress-ng to induce resource exhaustion (disk and CPU/Memory). While intended for debugging, these tools can be misused for denial-of-service attacks if triggered by malicious input.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 18, 2026, 12:59 PM
Security Audit — agent-trust-hub — systematic-debugging