debug
Pass
Audited by Gen Agent Trust Hub on Apr 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill extensively uses
run_commandand various CLI tools to perform debugging tasks. This includes running tests withbun, managing database states, searching the codebase withgrep, and establishing interactive shell sessions viarailway sshandneonctl. It also features the ability to execute arbitrary SQL queries using Neon-specific MCP tools. - [EXTERNAL_DOWNLOADS]: The skill instructions and scripts (
scripts/fetch_logs.sh,scripts/frontend_test.sh) direct the user to install several global NPM packages and CLI tools, includingagent-browser,neonctl, and@railway/cli. These resources are linked to well-known developer platforms or the skill's authoring vendor. - [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources, creating an indirect prompt injection surface.
- Ingestion points: The skill retrieves and analyzes output from
agent-browser snapshot(web page content) and application logs from external deployment services (railway logs). - Boundary markers: No explicit boundary markers or instructions to ignore embedded commands were found in the processing scripts.
- Capability inventory: The skill possesses high-privilege capabilities including full shell access (
run_command), database manipulation (mcp_mcp-server-neon_run_sql), and browser automation. - Sanitization: There is no evidence of sanitization, escaping, or validation of the external content before it is processed by the agent.
Audit Metadata