qa-debugging
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data such as application logs, stack traces, and production artifacts, which represents an indirect prompt injection surface.\n
- Ingestion points: SKILL.md workflows and
scripts/log_error_summary.pyprocess external log content and failure signatures.\n - Boundary markers: The skill includes a dedicated "External Input Normalization Boundary" protocol that mandates classification, canonicalization, and validation of inputs before downstream processing.\n
- Capability inventory: The skill utilizes local file reading in its Python scripts and references external tool execution through MCP servers.\n
- Sanitization: Instructions to sanitize and redact secrets/PII from logs and to treat external inputs as untrusted are explicitly included.\n- [EXTERNAL_DOWNLOADS]: The skill references the installation and use of third-party tools from external sources.\n
- Findings: It provides instructions in
references/stackoverflow-for-agents.mdfor adding a community-maintained Stack Overflow MCP server (@gscalzo/stackoverflow-mcp) via npx.\n - Context: It also references various well-known and trusted observability and debugging tools (e.g., OpenTelemetry, Grafana, Sentry, Mozilla's rr project) which are documented neutrally as standard industry practices.
Audit Metadata