rch
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes the
rchCLI and utilizes SSH to execute compilation and diagnostic commands on remote worker machines as part of its core build-offload functionality. - [INDIRECT_PROMPT_INJECTION]: The skill captures and processes external build logs and stderr to identify failure stages and routing decisions.
- Ingestion points: Captured stderr from compilation commands and tool hook responses during the build process.
- Boundary markers: The skill employs summary banners (e.g.,
[RCH] remote,[RCH] local) to identify and parse its own output within the terminal stream. - Capability inventory: Capabilities include local shell command execution, remote SSH command execution, and local configuration file writes.
- Sanitization: The skill performs specific string matching and diagnostic validation, although the source logs originate from untrusted external compilation processes.
- [PRIVILEGE_ESCALATION]: Troubleshooting procedures documented in the skill include the use of
sudofor remote worker maintenance tasks, such as repairing directory permissions, though these actions are strictly gated by explicit caller authorization requirements.
Audit Metadata