sbh
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill interacts with the host system using the
sbhcommand-line utility. It executes commands to inspect mount points, perform status checks, and run authorized cleanup or configuration tasks. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from the storage environment to make recovery decisions, representing an indirect injection surface.
- Ingestion points: Data from
sbh --json statusandsbh checkoutput (SKILL.md). - Boundary markers: The skill instructions explicitly require obtaining caller authority and establishing a factual baseline before any mutation (SKILL.md).
- Capability inventory: The skill possesses capabilities for file deletion, ballast release, and storage configuration modification (SKILL.md).
- Sanitization: The skill mandates an evidence-first approach, prioritizing reversible actions and strictly adhering to file protection vetoes (SKILL.md).
- [EXTERNAL_DOWNLOADS]: The skill includes a reference to a GitHub repository (github.com/Dicklesworthstone/storage_ballast_helper) for documentation and tool source information.
Audit Metadata