debug-remote

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes telemetry data, logs, and traces from external observability platforms, which represents an ingestion surface for potential indirect prompt injection attacks.
  • Ingestion points: External data enters the agent context through queries to telemetry backends (like OpenObserve), trace lookups, and log joins as described in SKILL.md and evidence-pack.md.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the gathered telemetry data.
  • Capability inventory: The skill strictly limits the agent to read-only operations and explicitly prohibits mutating actions such as POST requests, kubectl exec, image updates, or SSH access to production environments (SKILL.md, evidence-pack.md).
  • Sanitization: There are no requirements for the agent to sanitize, filter, or escape the content of the traces or logs before they are processed or included in the evidence pack.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 09:38 AM
Security Audit — agent-trust-hub — debug-remote