qa-debugging

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data such as application logs, stack traces, and production artifacts, which represents an indirect prompt injection surface.\n
  • Ingestion points: SKILL.md workflows and scripts/log_error_summary.py process external log content and failure signatures.\n
  • Boundary markers: The skill includes a dedicated "External Input Normalization Boundary" protocol that mandates classification, canonicalization, and validation of inputs before downstream processing.\n
  • Capability inventory: The skill utilizes local file reading in its Python scripts and references external tool execution through MCP servers.\n
  • Sanitization: Instructions to sanitize and redact secrets/PII from logs and to treat external inputs as untrusted are explicitly included.\n- [EXTERNAL_DOWNLOADS]: The skill references the installation and use of third-party tools from external sources.\n
  • Findings: It provides instructions in references/stackoverflow-for-agents.md for adding a community-maintained Stack Overflow MCP server (@gscalzo/stackoverflow-mcp) via npx.\n
  • Context: It also references various well-known and trusted observability and debugging tools (e.g., OpenTelemetry, Grafana, Sentry, Mozilla's rr project) which are documented neutrally as standard industry practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — qa-debugging