debugging-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes use of standard development and diagnostic tools including
git,pytest,docker,gdb,strace, andpy-spy. These tools are necessary for the skill's primary purpose of debugging and are scoped within theallowed-toolsconfiguration. - [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to ingest and analyze external data from log files and user-provided reports to identify bugs.
- Ingestion points: Application logs (
/var/log/app/*.log), correlation IDs from user input, and SQL query outputs. - Boundary markers: The instructions emphasize using specific, structured search queries (
grep -n,jq select) rather than reading unstructured text blocks, which limits the influence of the ingested data. - Capability inventory: The skill has access to
Bash,Read,Write,Edit,Grep, andGlobtools. - Sanitization: The skill explicitly recommends redaction at the logger level and provides SQL examples that focus on data metadata (information_schema) or distribution rather than individual sensitive values to prevent exposure.
Audit Metadata