diagnose-build-failure

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes build logs, which are external and untrusted data sources. There is a potential risk of indirect prompt injection if a build log contains malicious instructions; however, the skill limits the agent to identifying specific error signatures and reporting them to the user, reducing the risk of unintended actions.- [DATA_EXPOSURE]: The agent fetches build logs which may inadvertently contain sensitive information such as environment variables or secrets if they were printed to the console during the build process. The skill provides instructions to strip formatting but lacks specific instructions for scrubbing sensitive data before the log content is presented to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 06:35 AM
Security Audit — agent-trust-hub — diagnose-build-failure