linux-service-triage

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides logic to generate and guide the execution of shell commands for system diagnostics and service management (e.g., systemctl, ss, ps, dig).
  • [PRIVILEGE_ESCALATION]: Includes instructions for operations that typically require root or sudo access, such as modifying filesystem permissions and ownership using chmod and chown.
  • [PERSISTENCE]: Facilitates the creation of systemd service units and the modification of crontab files, which are standard mechanisms for maintaining long-term access or ensuring processes survive system restarts.
  • [DATA_EXFILTRATION]: Documentation in the integration-ideas.md file suggests workflows where system logs and diagnostic information are collected and transmitted to external messaging platforms via a notification script.
  • [DYNAMIC_EXECUTION]: The skill dynamically assembles shell command sequences based on log analysis to provide fix plans for execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and interpret data from potentially untrusted sources, such as system logs and application error logs.
  • Ingestion points: journalctl output and log files as specified in references/triage-commands.md.
  • Boundary markers: There are no explicit delimiters or instructions to prevent the agent from obeying commands embedded within the logs.
  • Capability inventory: Significant system access including service control, process termination (kill), and permission modification.
  • Sanitization: No sanitization or filtering of log content is implemented before the data is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 05:50 PM
Security Audit — agent-trust-hub — linux-service-triage