systematic-debugging

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze external data like error messages, stack traces, and system logs, which constitutes an attack surface for indirect prompt injection. This is a functional requirement for a debugging skill and no exploitation patterns were observed.\n
  • Ingestion points: Phase 1 (Root Cause Investigation) involves reading error messages, stack traces, and component logs from the execution environment.\n
  • Boundary markers: The skill does not mandate the use of delimiters when reading external content.\n
  • Capability inventory: The skill utilizes command execution (npm, security, bash) and file system access.\n
  • Sanitization: The instructions do not include specific sanitization steps for the ingested logs.\n- [COMMAND_EXECUTION]: The skill includes a utility script and examples that perform shell operations to diagnose system state.\n
  • Evidence: The find-polluter.sh script executes npm test on local files. SKILL.md provides examples of using macOS security and codesign utilities for debugging build and signing workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — systematic-debugging