electron-desktop-debugging

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to process external data sources such as application logs, crash reports, and console output, which constitutes an attack surface for instructions embedded in logs.\n
  • Ingestion points: Log gathering and triage steps defined in SKILL.md and references/01-evidence-and-triage.md.\n
  • Boundary markers: The skill does not specify the use of delimiters or 'ignore' instructions for the log data being analyzed.\n
  • Capability inventory: The skill is instructional and guides the agent's diagnostic logic and code modification suggestions; no automated tools are explicitly granted within the skill itself.\n
  • Sanitization: Comprehensive redaction guidelines for sensitive data (PII, credentials, tokens) are provided in references/04-logs-crashes-diagnostics.md, focusing on privacy and data safety.\n- [SAFE]: The skill demonstrates high security awareness by instructing the user to avoid placing signing materials, certificates, or passwords in diagnostic logs or repositories. It also promotes Electron security defaults like context isolation and disabling node integration in the renderer.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:30 PM
Security Audit — agent-trust-hub — electron-desktop-debugging