lynx-trace-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external trace data (e.g., .pftrace files) that could contain malicious instructions embedded within trace event names, thread names, or argument values. When the agent queries this data and interprets the output, it could be influenced by these hidden prompts.
  • Ingestion points: External trace files loaded via the --path parameter in the trace_query.bundle.cjs script, as documented in SKILL.md.
  • Boundary markers: No specific delimiters or "ignore embedded instructions" directives are present in the instructions to prevent the agent from following prompts found within tool outputs.
  • Capability inventory: The skill allows script execution (node), raw SQL queries (sql), and trace recording (readData), which could be misused if an injection is successful.
  • Sanitization: There are no documented steps for validating or sanitizing the content of the trace files before the agent processes them.
  • [EXTERNAL_DOWNLOADS]: The skill provides native support for fetching trace data from remote URLs. The CLI tool trace_query.bundle.cjs accepts a URL for the --path argument, allowing the agent to download and process data from any user-specified or prompt-specified internet location.
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute shell commands using node to run a local script bundle (trace_query.bundle.cjs). Additionally, the sql command allows for the execution of raw SQL queries against the trace processor database, which, while useful for analysis, provides a high-degree of control over the data retrieval process.
  • [DYNAMIC_EXECUTION]: The skill relies on a pre-bundled JavaScript file (trace_query.bundle.cjs) to perform its core logic. This script is executed at runtime via the node process, which is a form of dynamic execution of skill-provided assets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:54 AM
Security Audit — agent-trust-hub — lynx-trace-analysis