debug
Pass
Audited by Gen Agent Trust Hub on Mar 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing untrusted input from error messages and source code while possessing command execution capabilities.
- Ingestion points: The skill processes user-provided error descriptions ($ARGUMENTS) and reads files from the codebase (using Read, Glob, and Grep tools) in Phase 1 and Phase 3.
- Boundary markers: There are no explicit instructions or delimiters used to separate data from instructions or to warn the agent to ignore instructions embedded in the analyzed code or stack traces.
- Capability inventory: The skill utilizes powerful tools including Bash, Edit, Write, and Task, allowing it to modify files and execute arbitrary shell commands like 'npm test'.
- Sanitization: No sanitization or validation of the ingested content is performed before processing.
Audit Metadata