fullstack-debugger
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides several shell scripts (
diagnose.sh,check-cors.sh,inspect-cache.sh) and commands inSKILL.mdthat execute standard development tools includingnpm,npx,wrangler,curl,git, andlsof. These are used for environment verification, build testing, and remote resource health checks. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest and analyze application logs, error messages, and network responses which could potentially contain adversarial instructions.
- Ingestion points:
scripts/diagnose.sh(command output),scripts/check-cors.sh(HTTP headers), andscripts/inspect-cache.sh(Cloudflare KV data). - Boundary markers: Absent; the skill does not include specific delimiting or instructions to ignore embedded commands in logs.
- Capability inventory: The skill uses
Bashfor shell execution,Write/Editfor file management, andWebFetchfor network testing. - Sanitization: None detected for log or error message processing, which is standard for debugging tools.
Audit Metadata