bugfix

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it processes untrusted data from external sources and possesses high-privilege capabilities.
  • Ingestion points: The agent reads the codebase, system logs, and external web search results using Grep, Read, and WebSearch tools (SKILL.md).
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to distinguish between its own instructions and potentially malicious content embedded within the ingested data.
  • Capability inventory: The skill is authorized to use powerful tools including Bash (shell command execution), Edit, and Write (file system modification), allowing injected instructions to potentially trigger harmful actions.
  • Sanitization: The workflow lacks verification or sanitization steps to validate data retrieved from logs or the web before it influences the agent's logic or code changes.
  • [DATA_EXFILTRATION]: The skill's research phase involves performing web searches for exact error messages extracted from the local environment. If system logs contain sensitive information such as personal data, API tokens, or internal directory structures, this information could be inadvertently transmitted to external search providers.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 05:08 PM
Security Audit — agent-trust-hub — bugfix