troubleshoot-app

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that involves ingesting and processing data from potentially untrusted external sources, creating a surface for indirect prompt injection.
  • Ingestion points: The agent is instructed to capture user-visible browser evidence using Computer Use (Atlas/browser tabs), application logs, analytics (PostHog), and data from external providers (Stripe, Clerk, etc.).
  • Boundary markers: The instructions do not define specific delimiters or "ignore instructions" warnings to wrap the ingested external data when it is provided to the agent's context.
  • Capability inventory: The skill has significant capabilities, including implementing code fixes, adding regression tests, and executing CLI tools (e.g., pnpm exec convex, SQL queries).
  • Sanitization: While the skill explicitly instructs the agent to redact secrets and personal data from summaries, it does not include instructions to sanitize or escape malicious prompts that might be embedded in the browser UI, logs, or database records being analyzed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 11:26 PM
Security Audit — agent-trust-hub — troubleshoot-app