debugger
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The script
scripts/capture_breakpoints.pyuses theeval()function to evaluate user-provided watch expressions within the context of a paused program frame. While this is a standard feature for a debugger, it allows for arbitrary code execution if an agent provides a malicious expression. - [EXTERNAL_DOWNLOADS]: The installation script
scripts/install_vscode_bridge.shexecutesnpm ciduring the setup of the VS Code bridge extension. This command downloads and installs numerous third-party dependencies from the NPM registry at runtime without integrity verification. - [COMMAND_EXECUTION]: Extensive use of
subprocess.runandsubprocess.Popenoccurs across multiple scripts (scripts/vscode_walkthrough.py,scripts/generate_walkthrough_spec.py,scripts/open_in_vscode.py,scripts/vscode_dap_breakpoint_proof.py) to orchestrate debugger adapters, git commands, audio playback (aplay), and VS Code operations. - [CREDENTIALS_UNSAFE]: Several files contain hardcoded secrets used as test data for the skill's redaction features. For example,
fixtures/proofs/contains-secrets-valid.jsoncontains a test API key (sk-test-secret-1234567890) and a Bearer token. Similarly,scenarios/secret_capture/leaky.pyhardcodes a password and a JWT-shaped string for verification purposes. - [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection in
scripts/vscode_walkthrough.py. It retrieves module source code and live variable states and interpolates them directly into a prompt sent to the/asktool to generate explanations for the human user. There is no sanitization or clear boundary marking to prevent malicious content in the source code from influencing the agent's behavior. - [COMMAND_EXECUTION]: The
scripts/install_vscode_bridge.shscript executescode --install-extensionto force-install a locally built VS Code extension (.vsix) into the user's environment.
Audit Metadata