pm2
Warn
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill instructs the user to execute system-level configuration commands using administrative privileges.
- Specifically,
pm2 startupgenerates commands designed to be run withsudoto configure the operating system's init system (such as launchd or systemd) for boot persistence. - [PERSISTENCE]: The skill provides dedicated mechanisms to ensure Node.js processes remain running after system restarts.
- The
pm2 saveandpm2 startupcommands are utilized to register the current process list with the host system's service manager, establishing long-term persistence across reboots. - [COMMAND_EXECUTION]: The primary function of the skill is to provide a variety of shell commands to manage local processes.
- It includes commands for installation (
npm install), process lifecycle management (start, stop, reload, delete), and daemon management (pm2 kill). - [INDIRECT_PROMPT_INJECTION]: The use of log monitoring tools creates a vulnerability surface where the agent processes untrusted external data.
- Ingestion points: The
pm2 logscommand allows the agent to read the stdout and stderr streams of managed applications. - Boundary markers: The skill does not provide delimiters or warnings to ignore instructions that might be embedded in application log output.
- Capability inventory: The skill has access to process management, shell execution, and system service configuration.
- Sanitization: No sanitization or validation methods are mentioned for handling content retrieved from the logs before the agent interprets it.
Audit Metadata