debug-issue
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the lack of sanitization for processed external data.\n
- Ingestion points: The skill instructs the agent to gather and analyze evidence from external sources, specifically stack traces, logs, and reproduction steps provided by users or the environment (SKILL.md, Step 1 and Step 2).\n
- Boundary markers: There are no instructions to use delimiters or ignore embedded instructions within the gathered evidence, which could allow malicious content in logs to influence the agent's behavior.\n
- Capability inventory: The agent is guided to inspect codebases and run automated tests (Step 2 and Step 5), implying it possesses file system access and command execution capabilities.\n
- Sanitization: The skill does not provide mechanisms for sanitizing, escaping, or validating the external content before it is processed by the agent.
Audit Metadata