debug-issue

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the lack of sanitization for processed external data.\n
  • Ingestion points: The skill instructs the agent to gather and analyze evidence from external sources, specifically stack traces, logs, and reproduction steps provided by users or the environment (SKILL.md, Step 1 and Step 2).\n
  • Boundary markers: There are no instructions to use delimiters or ignore embedded instructions within the gathered evidence, which could allow malicious content in logs to influence the agent's behavior.\n
  • Capability inventory: The agent is guided to inspect codebases and run automated tests (Step 2 and Step 5), implying it possesses file system access and command execution capabilities.\n
  • Sanitization: The skill does not provide mechanisms for sanitizing, escaping, or validating the external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — debug-issue