systematic-debugging
Fail
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The file
phases/fault-injection.mdincludes instructions for the agent to execute system-level commands usingsudo(e.g.,sudo tc qdisc add dev eth0 root netem delay 500ms 100ms). This encourages the use of elevated privileges for network fault injection, creating a security risk if the environment is not strictly isolated. - [COMMAND_EXECUTION]: The provided shell utility
find-polluter.shaccepts a user-specified command (TEST_CMD) and executes it usingbash -cinside atimeoutwrapper. This pattern allows for arbitrary command execution on the host machine if the agent passes an unsanitized string derived from user input. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data, including application logs, test outputs, and bug reports. The workflow documentation lacks boundary markers or explicit instructions to ignore embedded commands in this data, allowing for an attack where a malicious log entry or bug report could influence the agent to execute dangerous commands using the skill's built-in tools.
- [COMMAND_EXECUTION]: The
phases/fault-injection.mdfile suggests using commands likefallocateandstress-ngto induce resource exhaustion (disk and CPU/Memory). While intended for debugging, these tools can be misused for denial-of-service attacks if triggered by malicious input.
Recommendations
- AI detected serious security threats
Audit Metadata