sre-engineer
Warn
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of
subprocess.runto interact with the system and cluster orchestrators. Evidence:SKILL.mdexecuteskubectl rollout restartusing arguments derived fromsys.argv. Evidence:references/automation-toil.mdexecutesdf,find,curl, andsystemctlcommands. Evidence:references/incident-chaos.mdexecutestc,kubectl delete, andiptablesviakubectl exec.\n- [DYNAMIC_EXECUTION]: TheAutomatedRunbookclass inreferences/automation-toil.mdexecutes arbitrary strings as shell commands viasubprocess.run(shell=True). This allows for complex shell piping and redirection which can be risky if inputs are not strictly controlled.\n- [PRIVILEGE_ESCALATION]: The skill implements procedures that require high-level system permissions, including restarting services (systemctl), modifying network interfaces (tc), and firewall rules (iptables).\n- [INDIRECT_PROMPT_INJECTION]: The skill creates a vulnerability surface by processing external data from a Prometheus API and using it in administrative commands without validation. Ingestion points: Theget_error_ratefunction inSKILL.mdfetches metrics from a remote Prometheus API. Boundary markers: None present. Capability inventory: Deployment restarts viakubectl. Sanitization: Input is interpolated into shell commands without explicit validation.
Audit Metadata