debugging-toolkit-smart-debug

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill directly interpolates external input via the $ARGUMENTS placeholder into the system prompt twice (in the Context section and at the end of the file).
  • Ingestion points: $ARGUMENTS used for 'Process issue from' and 'Issue to debug'.
  • Boundary markers: Absent. The skill lacks delimiters (e.g., XML tags or triple backticks) to separate untrusted data from instructions.
  • Capability inventory: The skill is capable of generating code fixes, regression tests, and querying external observability platforms (Sentry, DataDog, etc.).
  • Sanitization: Absent. There are no instructions to the agent to validate or ignore commands embedded within the issue reports.
  • [DYNAMIC_EXECUTION]: The workflow describes the automated generation of code fixes and regression tests (Steps 8 and 10). If the agent executes these generated scripts or tests automatically, a malicious issue report could lead to the execution of unintended code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 12:14 PM
Security Audit — agent-trust-hub — debugging-toolkit-smart-debug