lynx-debug-info-remapping
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/index.mjsuses theimport()function to dynamically load a file specified by thedebugInfoPathvariable. This path is passed as a command-line argument constructed from project structure and user input, which constitutes dynamic loading from a computed path. - Evidence:
const debugInfo = await import(debugInfoPath, { with: { type: 'json' } });inscripts/index.mjs. - [COMMAND_EXECUTION]: The skill instructions direct the agent to execute a
nodecommand using shell interpolation of user-provided variables$function_idand$pc_index. Without strict validation of these inputs before shell execution, this could lead to command injection vulnerabilities. - Evidence:
node ${CLAUDE_PLUGIN_ROOT}/skills/debug-info-remapping/scripts/index.mjs $PROJECT_DIR/[dist]/.rspeedy/[main]/debug-info.json $function_id $pc_indexinSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data that could be attacker-controlled and interpolates it into the agent's context during the remapping workflow.
- Ingestion points: The agent reads project files (
main-thread.js) and processes the output of the remapping script which parsesdebug-info.json(defined inSKILL.mdworkflow steps 4 and 5). - Boundary markers: None present; the skill does not use specific delimiters or instructions to ignore embedded commands in the processed files.
- Capability inventory: The skill has the capability to execute shell commands (
node) and read local filesystem data. - Sanitization: The
index.mjsscript performs basic numeric casting for ID parameters, but the agent does not perform sanitization on the file content before displaying it in the remapped stack trace.
Audit Metadata