sre-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous Python scripts that utilize subprocess.run to interact with system and cluster management tools. This includes using kubectl for Kubernetes operations, systemctl for service management, and networking tools like tc and iptables for chaos engineering experiments.\n- [DYNAMIC_EXECUTION]: The AutomatedRunbook implementation in references/automation-toil.md uses subprocess.run(shell=True) to execute command strings. This facilitates the automation of operational tasks but introduces a risk if commands are derived from untrusted inputs.\n- [INDIRECT_PROMPT_INJECTION]: The skill's workflow involves the agent querying and processing data from external monitoring sources such as Prometheus. This creates a surface for indirect prompt injection if the monitoring data contains malicious instructions.\n
  • Ingestion points: Prometheus API queries defined in SKILL.md and references/monitoring-alerting.md.\n
  • Boundary markers: None explicitly implemented to separate data from instructions in the provided templates.\n
  • Capability inventory: The skill possesses significant capabilities, including arbitrary shell command execution and Kubernetes cluster management.\n
  • Sanitization: The provided Python templates do not include explicit sanitization or validation of the data retrieved from external monitoring endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:49 PM
Security Audit — agent-trust-hub — sre-engineer