debugging-wizard

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to parse and analyze external data such as error messages, stack traces, and log entries. This creates a surface for indirect prompt injection where malicious instructions could be embedded in the data being debugged.
  • Ingestion points: Processes user-provided error logs, stack traces, and source code in SKILL.md and systematic-debugging.md.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands within the analyzed logs are provided in the skill instructions.
  • Capability inventory: The skill suggests using powerful diagnostic tools including pdb (Python), node --inspect (Node.js), dlv (Go), and git bisect which involve subprocess execution and environment manipulation.
  • Sanitization: No explicit sanitization or validation of the input logs/traces is described.
  • [SAFE]: The skill references standard, well-known debugging tools and libraries (e.g., github.com/davecgh/go-spew/spew) from trusted platforms (GitHub).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:18 PM
Security Audit — agent-trust-hub — debugging-wizard