ac-debug
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process potentially untrusted external data which creates an attack surface for indirect prompt injection.
- Ingestion points: Data enters the context during Phase 1 ('上下文收集与并行取证') where the agent and subagents read error logs, stack traces, configuration files, and recent code changes.
- Boundary markers: The skill implements a 'Hard Stop' in Phase 4 ('用户确认'), requiring the user to verify the diagnosis and proposed fix before execution, which serves as a manual boundary. It also uses structured templates for output.
- Capability inventory: The skill has the capability to read files (forensics) and write files (Phase 5 repair) using the main agent thread.
- Sanitization: There is no explicit mention of sanitization, filtering, or escaping of the content found in logs or code before it is integrated into the diagnostic reasoning process.
- [COMMAND_EXECUTION]: The skill describes a workflow that involves executing repairs and verification tests.
- Evidence: Phase 5 ('修复与验证') involves the agent implementing code fixes and running validation steps/tests based on the diagnosis. This is an intended function of a debugging skill but represents an active capability that relies on the accuracy of the preceding diagnostic phases.
Audit Metadata