systematic-debugging
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The
SKILL.mdfile contains instructions that encourage the agent to execute shell commands to inspect sensitive environment variables (env | grep IDENTITY) and the system keychain (security find-identity -v). While intended for debugging multi-component systems, these commands can expose credentials or signing identities to the agent context.- [COMMAND_EXECUTION]: The skill includes a utility scriptfind-polluter.shwhich executesnpm teston discovered files. The instructions inSKILL.mdandroot-cause-tracing.mdalso involve running shell commands andexecFileAsyncto investigate system state.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8). It is designed to ingest and process untrusted external data, such as stack traces and error messages, which could influence the agent's behavior. - Ingestion points: The agent is instructed to read stack traces and error messages from various components (
SKILL.md,root-cause-tracing.md). - Boundary markers: No specific delimiters or safety warnings are provided for the external data being analyzed.
- Capability inventory: The agent has access to shell execution (
SKILL.md),npm test(find-polluter.sh), andexecFileAsync(root-cause-tracing.md). - Sanitization: There is no evidence of sanitization or validation of the input data before it influences the agent's reasoning or command execution.
Audit Metadata