systematic-debugging

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external, untrusted data such as error messages, stack traces, and log outputs during debugging sessions.
  • Ingestion points: Error messages, stack traces, component logs, and test results (identified in SKILL.md and root-cause-tracing.md).
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when processing external error text.
  • Capability inventory: The skill utilizes shell commands for diagnostic evidence gathering and test execution, including 'find', 'ls', 'grep', and 'npm test' (identified in find-polluter.sh and SKILL.md).
  • Sanitization: No explicit sanitization or filtering logic is provided for the error data before it is presented to the agent for analysis.
  • [DYNAMIC_EXECUTION]: The skill includes a utility script that identifies and executes files dynamically at runtime.
  • Evidence: The find-polluter.sh script uses the find command to generate a list of test files based on a user-provided pattern and then executes each file using npm test within a loop.
  • [COMMAND_EXECUTION]: The instructions mandate the use of shell commands to gather environment data and system state for multi-component systems.
  • Evidence: SKILL.md provides templates for checking environment variables (env | grep), listing macOS keychains (security list-keychains), and verifying code signing identities (security find-identity). these are used for diagnostic instrumentation within a controlled build environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — systematic-debugging