lightrun-error-remediation-automation

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Integrates with the Lightrun MCP server via https://app.lightrun.com/mcp to provide investigation tools.\n- [COMMAND_EXECUTION]: Orchestrates runtime debugging tasks using Lightrun MCP tools for source discovery, snapshot capture, and metric collection.\n- [DATA_EXFILTRATION]: Communicates diagnostic runtime data and investigation metadata to the Lightrun platform and integrated durable storage solutions like Cursor AutomationMemory or Memories MCP.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting untrusted data from runtime outputs and source repositories (SKILL.md).\n
  • Ingestion points: Runtime evidence results (snapshots, call stacks, metrics) and repository source code.\n
  • Boundary markers: Not present; the skill lacks explicit delimiters for external content.\n
  • Capability inventory: Ability to create Pull Requests, perform local source edits, and execute Lightrun MCP tools defined in SKILL.md.\n
  • Sanitization: No explicit sanitization or filtering of external content is described.\n The risk is managed by the skill's requirement for hypothesis validation and mandatory result verification before code changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 04:51 PM
Security Audit — agent-trust-hub — lightrun-error-remediation-automation