workflow-debugger

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data including run transcripts and evaluation comments, which could contain instructions designed to manipulate the agent's analysis.
  • Ingestion points: Untrusted data enters the agent context via tools such as listRuns, getRevision, and listCases which fetch dynamic content from the Duvo platform.
  • Boundary markers: The skill provides a specific 'Inefficiency taxonomy' and mandates that all claims be grounded in evidence, which serves as a logical constraint on the agent's reasoning.
  • Capability inventory: The skill is limited to read-only platform operations (e.g., listRuns, getQueue, listAgentRevisions) and does not possess capabilities for file writing or general network exfiltration.
  • Sanitization: The instructions require the agent to quantify findings and hand off AOP modification tasks to a dedicated aop-writer skill, isolating the evaluation logic from the implementation logic.
  • [EXTERNAL_DOWNLOADS]: The skill references a specific command-line tool for platform interactions.
  • Evidence: The skill instructions mention the installation and usage of the @duvoai/cli Node.js package. This is a vendor-owned resource provided by duvoai to facilitate the skill's auditing functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 03:34 PM