managing-nginx
Warn
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes multiple shell commands to interact with the system environment and Nginx service. It specifically uses sudo (via
${NGINX_SUDO:+sudo}) to run commands such asnginx -t,nginx -T,ss, andnetstat. While necessary for Nginx management, this grants the agent elevated privileges on the host system. - [DATA_EXFILTRATION]: The skill accesses sensitive system resources, specifically Nginx access logs, error logs, and SSL certificate files (e.g.,
/var/log/nginx/*.log). This metadata can contain sensitive information about web traffic, client identities, and security configurations. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the processing of untrusted log data.
- Ingestion points: Nginx logs are read using
tailandawkcommands inSKILL.md. - Boundary markers: The skill does not implement boundary markers or instructions to ignore embedded commands within the ingested logs.
- Capability inventory: The skill possesses significant capabilities, including shell execution and administrative access via sudo.
- Sanitization: Log content is not sanitized or escaped before being processed by the agent.
Audit Metadata