diagnose

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No security threats identified. The skill implements a disciplined diagnostic workflow using standard development tools and practices. All provided scripts are benign templates for developer interaction.\n- [PROMPT_INJECTION]: Analysis of the indirect prompt injection surface (Category 8):\n
  • Ingestion points: The scripts/hitl-loop.template.sh script captures arbitrary user input, and the diagnosis methodology involves reading external traces, logs, and network payloads.\n
  • Boundary markers: No explicit delimiters or instructions are used to isolate or sanitize these inputs from the agent's instructions.\n
  • Capability inventory: The agent is encouraged to use tools like curl, git bisect, and browser automation scripts which could be targeted by malicious content in debugging artifacts.\n
  • Sanitization: No validation or filtering is implemented for the external content before processing. This surface is inherent to the primary purpose of bug diagnosis and is not considered a malicious finding.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 03:18 PM
Security Audit — agent-trust-hub — diagnose