chaos-engineer
Warn
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: MEDIUMPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill instructions include usage of
sudoto perform high-privilege system modifications, such as installing thestress-ngutility and modifying the/etc/hostssystem file to simulate network failures. - [EXTERNAL_DOWNLOADS]: Automated workflows in the skill fetch and apply remote Kubernetes manifests directly from
litmuschaos.github.io, an external source not explicitly defined in the trusted vendor environment. - [COMMAND_EXECUTION]: The skill relies on powerful CLI tools like
kubectl,aws-cli, andtoxiproxy-clito execute destructive actions, including instance termination, pod eviction, and network traffic manipulation as part of its core resilience testing functionality. - [INDIRECT_PROMPT_INJECTION]: Potential vulnerability surface detected where the agent processes external, untrusted data to make decisions.
- Ingestion points: The skill retrieves runtime data from Prometheus API queries and Kubernetes ChaosResult statuses.
- Boundary markers: The instructions lack explicit delimiters or warnings to ignore embedded instructions within the processed metric data.
- Capability inventory: The skill possesses capabilities to modify infrastructure state via
aws ec2 terminate-instancesandkubectl apply/deleteoperations. - Sanitization: There is no evidence of sanitization or strict schema validation for external data before it is used to determine if an experiment should be rolled back or considered successful.
Audit Metadata