diagnose-bug
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides explicit instructions to protect sensitive information by redacting secrets, credentials, and personally identifiable information (PII) from all diagnostic summaries and output reports before they are presented.
- [SAFE]: The operating contract enforces a requirement for explicit user confirmation before the agent can perform destructive or high-privilege actions, such as force-pushing to a repository, deleting data, or modifying resources outside the current project scope.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves processing external, potentially untrusted data sources to identify bug root causes.
- Ingestion points: The workflow ingests failing user inputs, request/response payloads, and runtime telemetry (logs, traces, metrics) during the reproduction and evidence-gathering steps.
- Boundary markers: The agent is guided by a formal operating contract requiring the definition of acceptance criteria and evidence checkpoints, which serves to maintain execution focus and mitigate data-driven instruction overrides.
- Capability inventory: The skill allows the agent to execute existing project test harnesses, run performance profiling tools, and implement code changes.
- Sanitization: The instructions emphasize verifying findings across multiple independent layers (such as unit tests vs. production logs) and validating causes against established specifications and contracts.
Audit Metadata