lynx-debug-info-remapping

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/index.mjs uses the import() function to dynamically load a file specified by the debugInfoPath variable. This path is passed as a command-line argument constructed from project structure and user input, which constitutes dynamic loading from a computed path.
  • Evidence: const debugInfo = await import(debugInfoPath, { with: { type: 'json' } }); in scripts/index.mjs.
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute a node command using shell interpolation of user-provided variables $function_id and $pc_index. Without strict validation of these inputs before shell execution, this could lead to command injection vulnerabilities.
  • Evidence: node ${CLAUDE_PLUGIN_ROOT}/skills/debug-info-remapping/scripts/index.mjs $PROJECT_DIR/[dist]/.rspeedy/[main]/debug-info.json $function_id $pc_index in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data that could be attacker-controlled and interpolates it into the agent's context during the remapping workflow.
  • Ingestion points: The agent reads project files (main-thread.js) and processes the output of the remapping script which parses debug-info.json (defined in SKILL.md workflow steps 4 and 5).
  • Boundary markers: None present; the skill does not use specific delimiters or instructions to ignore embedded commands in the processed files.
  • Capability inventory: The skill has the capability to execute shell commands (node) and read local filesystem data.
  • Sanitization: The index.mjs script performs basic numeric casting for ID parameters, but the agent does not perform sanitization on the file content before displaying it in the remapped stack trace.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 09:00 AM
Security Audit — agent-trust-hub — lynx-debug-info-remapping