systematic-debugging

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The SKILL.md file contains instructions that encourage the agent to execute shell commands to inspect sensitive environment variables (env | grep IDENTITY) and the system keychain (security find-identity -v). While intended for debugging multi-component systems, these commands can expose credentials or signing identities to the agent context.- [COMMAND_EXECUTION]: The skill includes a utility script find-polluter.sh which executes npm test on discovered files. The instructions in SKILL.md and root-cause-tracing.md also involve running shell commands and execFileAsync to investigate system state.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8). It is designed to ingest and process untrusted external data, such as stack traces and error messages, which could influence the agent's behavior.
  • Ingestion points: The agent is instructed to read stack traces and error messages from various components (SKILL.md, root-cause-tracing.md).
  • Boundary markers: No specific delimiters or safety warnings are provided for the external data being analyzed.
  • Capability inventory: The agent has access to shell execution (SKILL.md), npm test (find-polluter.sh), and execFileAsync (root-cause-tracing.md).
  • Sanitization: There is no evidence of sanitization or validation of the input data before it influences the agent's reasoning or command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — systematic-debugging