chaos-engineer

Warn

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill instructions include usage of sudo to perform high-privilege system modifications, such as installing the stress-ng utility and modifying the /etc/hosts system file to simulate network failures.
  • [EXTERNAL_DOWNLOADS]: Automated workflows in the skill fetch and apply remote Kubernetes manifests directly from litmuschaos.github.io, an external source not explicitly defined in the trusted vendor environment.
  • [COMMAND_EXECUTION]: The skill relies on powerful CLI tools like kubectl, aws-cli, and toxiproxy-cli to execute destructive actions, including instance termination, pod eviction, and network traffic manipulation as part of its core resilience testing functionality.
  • [INDIRECT_PROMPT_INJECTION]: Potential vulnerability surface detected where the agent processes external, untrusted data to make decisions.
  • Ingestion points: The skill retrieves runtime data from Prometheus API queries and Kubernetes ChaosResult statuses.
  • Boundary markers: The instructions lack explicit delimiters or warnings to ignore embedded instructions within the processed metric data.
  • Capability inventory: The skill possesses capabilities to modify infrastructure state via aws ec2 terminate-instances and kubectl apply/delete operations.
  • Sanitization: There is no evidence of sanitization or strict schema validation for external data before it is used to determine if an experiment should be rolled back or considered successful.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — chaos-engineer