debug-ops

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous examples of bash-based diagnostic commands, including system call tracing (strace), network sniffing (tcpdump), and git operations (bisect). These capabilities are intended for and limited to the skill's purpose of enabling systematic debugging operations.- [EXTERNAL_DOWNLOADS]: The instructional content references several standard and reputable third-party utilities for performance profiling and diagnostics, such as clinic.js, 0x, py-spy, and memray. These tools are legitimate components of modern developer workflows.- [PROMPT_INJECTION]: The skill documents an attack surface for indirect prompt injection.
  • Ingestion points: The agent is tasked with ingesting and analyzing potentially untrusted data from external sources, including application logs, stack traces, and API payloads, as specified in the reproduction and isolation workflows.
  • Boundary markers: The provided instructions do not include explicit delimiters or defensive prompts to prevent the agent from misinterpreting data content as instructions.
  • Capability inventory: The skill requires the Bash and Read/Write tools, providing a broad capability set that could be exploited if an injection occurs.
  • Sanitization: There are no documented procedures for sanitizing or escaping diagnostic data before it is analyzed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 11:30 AM