skills/delorenj/skills/pm2/Gen Agent Trust Hub

pm2

Warn

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill instructs the user to execute system-level configuration commands using administrative privileges.
  • Specifically, pm2 startup generates commands designed to be run with sudo to configure the operating system's init system (such as launchd or systemd) for boot persistence.
  • [PERSISTENCE]: The skill provides dedicated mechanisms to ensure Node.js processes remain running after system restarts.
  • The pm2 save and pm2 startup commands are utilized to register the current process list with the host system's service manager, establishing long-term persistence across reboots.
  • [COMMAND_EXECUTION]: The primary function of the skill is to provide a variety of shell commands to manage local processes.
  • It includes commands for installation (npm install), process lifecycle management (start, stop, reload, delete), and daemon management (pm2 kill).
  • [INDIRECT_PROMPT_INJECTION]: The use of log monitoring tools creates a vulnerability surface where the agent processes untrusted external data.
  • Ingestion points: The pm2 logs command allows the agent to read the stdout and stderr streams of managed applications.
  • Boundary markers: The skill does not provide delimiters or warnings to ignore instructions that might be embedded in application log output.
  • Capability inventory: The skill has access to process management, shell execution, and system service configuration.
  • Sanitization: No sanitization or validation methods are mentioned for handling content retrieved from the logs before the agent interprets it.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — pm2