recursive-debugging
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow for processing untrusted data from external sources, such as error logs and stack traces, which represents an indirect prompt injection surface.\n
- Ingestion points: The skill instructs the agent to record verbatim error messages, stack traces, and data flow values into the Phase 1.5 artifact (Section 1.1, 1.4, 1.5).\n
- Boundary markers: The provided template uses standard Markdown headers for separation but lacks specific instructions to the agent to disregard potential instructions hidden within the logged content.\n
- Capability inventory: The debugging workflow requires the agent to have permissions for filesystem traversal, file reading, and command execution for diagnostic purposes.\n
- Sanitization: There are no provisions for sanitizing or filtering external data before it is processed by the agent or recorded in the project files.
Audit Metadata