debugging-master
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is composed strictly of Markdown documentation and reference files. It defines an identity and methodology for debugging tasks without including any functional code or scripts that could execute on the host system.
- [NO_CODE]: There are no scripts, binaries, or configuration files that trigger execution. The skill provides instructions and examples in natural language and pseudocode.
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to interact with and modify user-supplied code to diagnose bugs. This creates an inherent surface for indirect prompt injection if the user's code contains malicious instructions intended to manipulate the agent. However, this is a fundamental aspect of the debugging task and not a unique vulnerability of the skill itself.
- Ingestion points: User-provided buggy code and error logs processed in the agent context (SKILL.md, references/patterns.md).
- Boundary markers: The instructions do not define delimiters or special handling to isolate user-provided code from instructions.
- Capability inventory: The skill possesses no internal capabilities, relying on the agent's existing shell or file-system tools.
- Sanitization: There are no instructions for sanitizing or escaping user-provided code before processing.
Audit Metadata