managing-puppet

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of local shell execution to perform Puppet operations. Evidence includes calls to puppet, curl, jq, find, and sed across various management tasks.
  • [DATA_EXFILTRATION]: The discovery script accesses sensitive Puppet SSL files, specifically private keys located in /etc/puppetlabs/puppet/ssl/private_keys/, to authenticate requests to the Puppet Server status API. While this is a standard requirement for Puppet administration, it represents an access pattern to highly sensitive credentials.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting untrusted data that is then interpolated into shell commands and API queries.
  • Ingestion points: Variables such as $NODE, $MODULE, and $ENVIRONMENT are accepted as arguments in multiple scripts within SKILL.md.
  • Boundary markers: None are present to delimit user-provided data from command logic.
  • Capability inventory: The skill has access to puppet, curl (including POST/GET to localhost and the Puppet Server), find, and sed within SKILL.md.
  • Sanitization: There is no evidence of input validation or sanitization for the provided variables before they are used in shell command interpolation or URL construction.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 11:30 AM
Security Audit — agent-trust-hub — managing-puppet