debugger-detective

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [COMMAND_EXECUTION]: The skill frequently utilizes the Bash tool to interact with the claudemem CLI, perform index checks, and execute shell scripts for verifying file timestamps and repository status.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes and presents contents from an external codebase, creating a surface for indirect instructions to influence the agent. Ingestion points: Symbol definitions, call chains, and state mutation data are ingested from the codebase via claudemem output in SKILL.md. Boundary markers: There are no explicit instructions or delimiters designed to isolate analyzed code content from the agent's control flow. Capability inventory: The agent has access to Bash, Task, and Read tools, which could be misused if instructions embedded in the analyzed code are followed. Sanitization: No sanitization or safety-filtering is applied to the raw output of the AST analysis tool.
  • [METADATA_POISONING]: The skill contains a maintenance note at the footer attributing the plugin to 'MadAppGang', which differs from the provided author identity 'involvex'. While likely a template artifact, this is an inconsistency in the metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 08:19 PM
Security Audit — agent-trust-hub — debugger-detective