debugger

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The script scripts/capture_breakpoints.py uses the eval() function to evaluate user-provided watch expressions within the context of a paused program frame. While this is a standard feature for a debugger, it allows for arbitrary code execution if an agent provides a malicious expression.
  • [EXTERNAL_DOWNLOADS]: The installation script scripts/install_vscode_bridge.sh executes npm ci during the setup of the VS Code bridge extension. This command downloads and installs numerous third-party dependencies from the NPM registry at runtime without integrity verification.
  • [COMMAND_EXECUTION]: Extensive use of subprocess.run and subprocess.Popen occurs across multiple scripts (scripts/vscode_walkthrough.py, scripts/generate_walkthrough_spec.py, scripts/open_in_vscode.py, scripts/vscode_dap_breakpoint_proof.py) to orchestrate debugger adapters, git commands, audio playback (aplay), and VS Code operations.
  • [CREDENTIALS_UNSAFE]: Several files contain hardcoded secrets used as test data for the skill's redaction features. For example, fixtures/proofs/contains-secrets-valid.json contains a test API key (sk-test-secret-1234567890) and a Bearer token. Similarly, scenarios/secret_capture/leaky.py hardcodes a password and a JWT-shaped string for verification purposes.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection in scripts/vscode_walkthrough.py. It retrieves module source code and live variable states and interpolates them directly into a prompt sent to the /ask tool to generate explanations for the human user. There is no sanitization or clear boundary marking to prevent malicious content in the source code from influencing the agent's behavior.
  • [COMMAND_EXECUTION]: The scripts/install_vscode_bridge.sh script executes code --install-extension to force-install a locally built VS Code extension (.vsix) into the user's environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — debugger