systematic-debugging
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to "Read Error Messages Carefully" and treat them as sources for the "exact solution," creating a vector where malicious output from external tools could influence the agent's actions if it follows instructions embedded in error logs. 1. Ingestion points:
SKILL.md(error logs, stack traces, and diagnostic instrumentation output). 2. Boundary markers: Absent; the process focuses on logical analysis rather than content sanitization. 3. Capability inventory: Shell execution vianpm testand diagnostic utilities likecodesignandsecurity. 4. Sanitization: Absent. - [COMMAND_EXECUTION]: The skill provides and encourages the use of shell scripts and commands for root cause investigation. Evidence:
find-polluter.shexecutesnpm teston files identified viafind;SKILL.mdsuggests using commands likesecurity list-keychains,security find-identity -v, andcodesignfor build verification. These tools represent a capability surface for local command execution. - [PROMPT_INJECTION]: The inclusion of "Pressure Test" files (e.g.,
test-pressure-1.md) uses imperative language ("IMPORTANT: This is a real scenario", "make the actual decision") to simulate high-pressure environments. While intended for self-testing and calibration, these files contain simulated user pressure designed to override the skill's own rules, which could be misconstrued by the agent as legitimate overrides if processed outside the testing context.
Audit Metadata