skills/boshu2/agentops/using-gc/Gen Agent Trust Hub

using-gc

Warn

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of CLI tools including ao, gc, tmux, and curl to manipulate the local environment, monitor processes, and interact with network services.
  • [PRIVILEGE_ESCALATION]: The ao gc prepare command is designed to bypass interactive security dialogs in the Codex application. It achieves this by programmatically modifying the $CODEX_HOME/config.toml file to mark specific directories and hooks as trusted, allowing automation to proceed without user confirmation.
  • [EXTERNAL_DOWNLOADS]: The instructions direct the user to add and use an external "community" registry (https://registry.gascity.com/registry.toml) for downloading software packs. This source is not verified as a trusted vendor, posing a risk of downloading unvetted content.
  • [DYNAMIC_EXECUTION]: The prepare command generates and installs "AgentOps-owned wrappers" at specific formula check paths within the rig's .gc runtime. This involves creating executable files locally to intercept or extend runtime behavior.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a monitoring loop that reads data from untrusted sources, such as the gc mail inbox and tmux console panes. This data is used to drive agent actions without explicit sanitization.
  • Ingestion points: gc mail inbox, tmux capture-pane, and supervisor API responses.
  • Boundary markers: None identified; instructions suggest acting on signals found in prose.
  • Capability inventory: Significant operational capabilities including operate_gas_city and configure_codex_trust.
  • Sanitization: No evidence of data validation or instruction filtering for ingested content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 28, 2026, 12:51 AM
Security Audit — agent-trust-hub — using-gc