managing-puppet
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of local shell execution to perform Puppet operations. Evidence includes calls to
puppet,curl,jq,find, andsedacross various management tasks. - [DATA_EXFILTRATION]: The discovery script accesses sensitive Puppet SSL files, specifically private keys located in
/etc/puppetlabs/puppet/ssl/private_keys/, to authenticate requests to the Puppet Server status API. While this is a standard requirement for Puppet administration, it represents an access pattern to highly sensitive credentials. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting untrusted data that is then interpolated into shell commands and API queries.
- Ingestion points: Variables such as
$NODE,$MODULE, and$ENVIRONMENTare accepted as arguments in multiple scripts withinSKILL.md. - Boundary markers: None are present to delimit user-provided data from command logic.
- Capability inventory: The skill has access to
puppet,curl(including POST/GET to localhost and the Puppet Server),find, andsedwithinSKILL.md. - Sanitization: There is no evidence of input validation or sanitization for the provided variables before they are used in shell command interpolation or URL construction.
Audit Metadata