ce-debug

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources such as issue trackers (GitHub, Linear, Jira, Sentry) and user-provided bug descriptions to drive investigation and reproduction. A malicious ticket could attempt to inject instructions to manipulate the agent's behavior. * Ingestion points: Ingests user-provided descriptions and fetches full comment threads from external issue URLs in references/investigate.md. * Boundary markers: Lacks explicit boundary markers or warnings when processing fetched issue content. * Capability inventory: Extensive shell execution and file write capabilities across all phases. * Sanitization: Redacts secrets from output but does not sanitize instructions in external input data.
  • [COMMAND_EXECUTION]: The skill is designed to execute arbitrary shell commands for bug reproduction and git operations. Evidence in references/investigate.md and references/fix.md involves running tests, scripts, and CLI commands provided in or derived from the bug report.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 06:11 AM
Security Audit — agent-trust-hub — ce-debug