managing-wireguard
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes several system-level commands to monitor and manage WireGuard interfaces.
- It uses
wg show,ip addr,ip route, andlsto discover the current state of the VPN. - It utilizes
${WG_SUDO:+sudo}to execute commands with elevated privileges when necessary for WireGuard management. - Scripts include logic for analyzing handshakes, transfer statistics, and tunnel health.
- [CREDENTIALS_UNSAFE]: The skill references sensitive configuration paths and data.
- It accesses
/etc/wireguard/*.confto list configuration files. - Crucially, it includes explicit safety rules: 'NEVER display or log private keys — use wg show which redacts them' and 'Config file permissions: WireGuard configs contain private keys — must be 600 or 640'.
- [PROMPT_INJECTION]: The skill uses authoritative language ('MANDATORY', 'NEVER', 'ALWAYS') and 'Counter-Rationalizations' to guide the agent toward safe, structured behavior and prevent hallucinations or shortcuts during VPN management.
Audit Metadata