diagnostic-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a utility script named 'find-polluter.sh' that automates test execution using the 'npm test' command to identify state-leaking tests.
- [COMMAND_EXECUTION]: The instructions in 'SKILL.md' provide examples of diagnostic shell commands, such as using 'env' to check environment variables and the 'security' tool to verify keychain identities.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external diagnostic data like error logs and stack traces. This creates an attack surface where untrusted data could attempt to influence the agent's logic, which the skill addresses through a rigorous verification process.
- Ingestion points: The agent processes error messages and logs provided by the user or system.
- Boundary markers: Instructions focus on thorough reading of stack traces but do not define specific data delimiters.
- Capability inventory: The skill includes a bash script for running tests and suggests instrumentation commands.
- Sanitization: Risk is managed through systematic hypothesis testing and manual verification of all fixes.
Audit Metadata