sync-debug
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from execution logs and source code, creating a surface for indirect prompt injection.
- Ingestion points: Output from
ntn workers runs logsand local filesrc/index.ts. - Boundary markers: The instructions do not define specific delimiters or warnings to ignore embedded instructions in the logs or code.
- Capability inventory: The agent has access to
Bashfor command execution andWrite/Editfor file modifications. - Sanitization: There is no explicit sanitization or validation of external content before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill uses the
ntnCLI to perform administrative tasks such as listing environment variables (ntn workers env list) and viewing OAuth tokens (ntn workers oauth token). These are standard diagnostic functions for the vendor's platform.
Audit Metadata