sre-engineer

Warn

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of subprocess.run to interact with the system and cluster orchestrators. Evidence: SKILL.md executes kubectl rollout restart using arguments derived from sys.argv. Evidence: references/automation-toil.md executes df, find, curl, and systemctl commands. Evidence: references/incident-chaos.md executes tc, kubectl delete, and iptables via kubectl exec.\n- [DYNAMIC_EXECUTION]: The AutomatedRunbook class in references/automation-toil.md executes arbitrary strings as shell commands via subprocess.run(shell=True). This allows for complex shell piping and redirection which can be risky if inputs are not strictly controlled.\n- [PRIVILEGE_ESCALATION]: The skill implements procedures that require high-level system permissions, including restarting services (systemctl), modifying network interfaces (tc), and firewall rules (iptables).\n- [INDIRECT_PROMPT_INJECTION]: The skill creates a vulnerability surface by processing external data from a Prometheus API and using it in administrative commands without validation. Ingestion points: The get_error_rate function in SKILL.md fetches metrics from a remote Prometheus API. Boundary markers: None present. Capability inventory: Deployment restarts via kubectl. Sanitization: Input is interpolated into shell commands without explicit validation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 4, 2026, 09:18 PM
Security Audit — agent-trust-hub — sre-engineer