cpanel-backup
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill generates shell commands using user-supplied data like hostnames and file names, which presents a surface for command injection if the calling agent does not perform sanitization.\n
- Ingestion points: User-supplied FTP credentials and file names for restoration.\n
- Boundary markers: None specified to prevent the agent from obeying instructions embedded in the data.\n
- Capability inventory: Shell command execution via the
cpanelCLI.\n - Sanitization: No mention of input validation or escaping procedures.\n- [CREDENTIALS_UNSAFE]: The
backup:create-ftpcommand documentation includes a password as a plaintext argument. This is an insecure practice that can lead to credential exposure in system logs or process lists.
Audit Metadata