sync-debug

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from execution logs and source code, creating a surface for indirect prompt injection.
  • Ingestion points: Output from ntn workers runs logs and local file src/index.ts.
  • Boundary markers: The instructions do not define specific delimiters or warnings to ignore embedded instructions in the logs or code.
  • Capability inventory: The agent has access to Bash for command execution and Write/Edit for file modifications.
  • Sanitization: There is no explicit sanitization or validation of external content before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill uses the ntn CLI to perform administrative tasks such as listing environment variables (ntn workers env list) and viewing OAuth tokens (ntn workers oauth token). These are standard diagnostic functions for the vendor's platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:37 AM
Security Audit — agent-trust-hub — sync-debug