windsurf-debugging-ai

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external, untrusted data such as error logs and stack traces, which represents a potential surface for indirect prompt injection. Ingestion points: The skill ingests user-provided stack traces, error messages, and application code as described in SKILL.md and references/implementation.md. Boundary markers: No explicit delimiters or instructions are provided to the agent to treat external debug data as untrusted content. Capability inventory: The skill is configured to use Bash, Read, Grep, and Glob tools. Sanitization: The instructions do not define methods for sanitizing or validating the ingested debug data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:48 AM
Security Audit — agent-trust-hub — windsurf-debugging-ai