managing-wireguard

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes several system-level commands to monitor and manage WireGuard interfaces.
  • It uses wg show, ip addr, ip route, and ls to discover the current state of the VPN.
  • It utilizes ${WG_SUDO:+sudo} to execute commands with elevated privileges when necessary for WireGuard management.
  • Scripts include logic for analyzing handshakes, transfer statistics, and tunnel health.
  • [CREDENTIALS_UNSAFE]: The skill references sensitive configuration paths and data.
  • It accesses /etc/wireguard/*.conf to list configuration files.
  • Crucially, it includes explicit safety rules: 'NEVER display or log private keys — use wg show which redacts them' and 'Config file permissions: WireGuard configs contain private keys — must be 600 or 640'.
  • [PROMPT_INJECTION]: The skill uses authoritative language ('MANDATORY', 'NEVER', 'ALWAYS') and 'Counter-Rationalizations' to guide the agent toward safe, structured behavior and prevent hallucinations or shortcuts during VPN management.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:21 PM
Security Audit — agent-trust-hub — managing-wireguard