skills/sentimony/skills/debugging/Gen Agent Trust Hub

debugging

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill methodology involves processing potentially untrusted data including logs, API responses, tool outputs, and HTML content (Ingestion point: SKILL.md Security Model section). The skill includes explicit instructions that instruction-shaped text within these sources has no authority to change scope or run commands (Boundary marker: SKILL.md Security Model section). The agent possesses capabilities to execute reproducers, tests, the application, and implement causal fixes in the codebase (Capability inventory: SKILL.md Security Model and lifecycle sections). Specific safety guidelines are provided to redact or minimize tokens, passwords, and PII (Sanitization: SKILL.md Safety and cleanup section). This combination of untrusted data ingestion and significant system access creates a surface for indirect prompt injection.
  • [COMMAND_EXECUTION]: The skill methodology requires the agent to execute various shell commands, including running the application under investigation, executing test suites, and using version control tools like git bisect. While these actions are fundamental to the skill's primary purpose of technical debugging, they constitute a high-privilege interaction with the host system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:12 AM
Security Audit — agent-trust-hub — debugging