chaos-engineer

Warn

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill provides scripts and instructions that utilize sudo to perform restricted system actions, such as modifying the /etc/hosts file for DNS failure simulation and installing performance-testing packages like stress-ng.
  • [COMMAND_EXECUTION]: The skill generates and executes high-impact infrastructure commands to simulate failures. This includes terminating EC2 instances via the AWS CLI (aws ec2 terminate-instances), deleting Kubernetes pods and resources (kubectl delete), and triggering database failovers.
  • [EXTERNAL_DOWNLOADS]: The skill fetches external configuration files, specifically Kubernetes manifests from litmuschaos.github.io (a well-known chaos engineering project), and encourages the installation of third-party tools via brew and apt-get.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data such as system architecture descriptions and performance metrics to design experiments, creating a surface where malicious instructions embedded in system documentation could influence the generated failure injection logic.
  • Ingestion points: Reads experiment design templates and game day scenarios in references/experiment-design.md and references/game-days.md.
  • Boundary markers: No explicit boundary markers or warnings are used to instruct the agent to ignore potentially malicious content within input data.
  • Capability inventory: The skill has access to the filesystem, network (via requests), and powerful CLI tools (kubectl, aws, toxiproxy-cli).
  • Sanitization: There is no evidence of input validation or escaping for external parameters used in the generated code and manifests.
  • [DYNAMIC_EXECUTION]: The skill dynamically generates and executes failure injection scripts (Bash and Python) and Kubernetes Custom Resource manifests based on runtime user input and environment analysis.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 4, 2026, 09:19 PM
Security Audit — agent-trust-hub — chaos-engineer