specsfy-specialist-debugging

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or data exfiltration were detected. The skill defines a standard, multi-step process for reproduction and hypothesis-driven debugging.
  • [NO_CODE]: The skill consists entirely of instructional markdown and configuration metadata, with no executable scripts, binaries, or automated tasks provided.
  • [EXTERNAL_DOWNLOADS]: References to external sources in references/standards.md point to official documentation for Git, Chrome DevTools, Python, PostgreSQL, and OpenTelemetry. These are trusted technical resources used for informational purposes.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes user-provided diagnostic data and bug reports (SKILL.md).
  • Ingestion points: User-provided descriptions of symptoms, expected/observed behavior, and environment logs.
  • Boundary markers: None present; the skill does not instruct the agent to use specific delimiters for user data.
  • Capability inventory: The skill allows for identifying root causes and, if authorized, correcting code and adding regression tests.
  • Sanitization: None present; the skill does not define filtering or escaping for processed logs. This represents a standard operational surface for a diagnostic tool rather than a malicious finding.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 09:19 PM
Security Audit — agent-trust-hub — specsfy-specialist-debugging