chromatic-workflow-debug

Pass

Audited by Gen Agent Trust Hub on Apr 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of Markdown documentation and templates for debugging. It does not contain executable scripts, automated network requests, or hardcoded credentials.
  • [PROMPT_INJECTION]: Ingestion points: User-provided error messages, logs, and git command output (SKILL.md, template.md). Boundary markers: Absent. Capability inventory: Generates formatted text output (Diagnosis Card); no high-risk capabilities like filesystem writes or automated shell execution are present. Sanitization: Absent. The skill creates an indirect prompt injection surface (Category 8) by processing untrusted diagnostic data, but the lack of autonomous tools and the focused scope of the diagnosis mitigate the risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 15, 2026, 05:32 PM