workflow-debugger
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data including run transcripts and evaluation comments, which could contain instructions designed to manipulate the agent's analysis.
- Ingestion points: Untrusted data enters the agent context via tools such as
listRuns,getRevision, andlistCaseswhich fetch dynamic content from the Duvo platform. - Boundary markers: The skill provides a specific 'Inefficiency taxonomy' and mandates that all claims be grounded in evidence, which serves as a logical constraint on the agent's reasoning.
- Capability inventory: The skill is limited to read-only platform operations (e.g.,
listRuns,getQueue,listAgentRevisions) and does not possess capabilities for file writing or general network exfiltration. - Sanitization: The instructions require the agent to quantify findings and hand off AOP modification tasks to a dedicated
aop-writerskill, isolating the evaluation logic from the implementation logic. - [EXTERNAL_DOWNLOADS]: The skill references a specific command-line tool for platform interactions.
- Evidence: The skill instructions mention the installation and usage of the
@duvoai/cliNode.js package. This is a vendor-owned resource provided by duvoai to facilitate the skill's auditing functionality.
Audit Metadata