termux-sshd
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes standard system utilities like
sshd,pkill,stat, andgrepto configure the SSH service and verify its status. These commands are executed locally within the Termux environment and are appropriate for the skill's administrative purpose. - [INDIRECT_PROMPT_INJECTION]: The skill includes an attack surface for indirect injection as it processes user-provided public keys for SSH access.
- Ingestion points: Client public keys used to populate the
~/.ssh/authorized_keysfile as described inSKILL.md. - Boundary markers: The skill relies on the user following specific setup steps rather than automated prompt interpolation.
- Capability inventory: The skill can write to the filesystem (SSH keys), manage the
sshddaemon, and read specific configuration lines fromsshd_configusing thescripts/check-sshd.shscript. - Sanitization: The instructions explicitly require setting restrictive file permissions (mode 700 for the SSH directory and 600 for the authorized_keys file) to ensure the integrity of the authentication process.
Audit Metadata