runtime-debug

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill creates a vulnerability surface for indirect prompt injection by instructing the agent to ingest and analyze data from external log streams and observability tools. Evidence Chain: 1. Ingestion points: observability MCPs (e.g., Datadog) and platform log streams (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Indirectly uses observability tools to fetch external data. 4. Sanitization: Absent.
  • [PROMPT_INJECTION]: The instructions include a directive to ignore 'test secrets' and 'fail-open' configurations in lab or ephemeral environments. This guidance may lead the agent to overlook legitimate security risks or be used as a justification to maintain insecure environment variables during an automated audit.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 11:08 PM
Security Audit — agent-trust-hub — runtime-debug