debug-investigator
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses local shell commands including
grepfor code search andnpm run lintandnpx tsc --noEmitfor project verification (SKILL.md Steps 1 and 4). These are standard development practices for root-cause analysis and do not involve unauthorized privilege escalation or remote script piping.\n- [PROMPT_INJECTION]: The skill ingests untrusted data from bug reports and Slack threads (SKILL.md Trigger Conditions). While this represents an indirect prompt injection surface, the risk is mitigated by a mandatory human-approval gate in Step 3. Ingestion points: External symptom descriptions in SKILL.md. Boundary markers: None on input, but Step 3 requires user confirmation. Capability inventory: File reading (grep), local command execution (tsc, lint). Sanitization: None specified for input data.\n- [SAFE]: No remote code execution from unknown sources, credential harvesting, persistence mechanisms, or obfuscated content were detected. All external tool references (npx, npm) are to well-known services used for their intended development purposes.
Audit Metadata