security-monitor
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEDATA_EXFILTRATIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXPOSURE_EXFILTRATION]: The script
scripts/monitor.cjsaccesses sensitive file paths and directories normally restricted to root users. - It checks for modifications and credential presence in
/root/clawd/.env,/root/clawd/skills/.env, and/root/clawd/config. - While the script currently only logs the presence of specific API service keywords (e.g., 'TWITTER', 'KAPSO') and file modification timestamps rather than the secret values themselves, the capability to read these files constitutes a data exposure risk.
- [PRIVILEGE_ESCALATION]: The skill requires high-level system privileges to operate correctly, as seen in
scripts/monitor.cjs. - The
checkFailedLoginsfunction attempts to read/var/log/auth.logand/var/log/syslog, which are typically only readable by root or members of theadmgroup. - The script monitors files within the
/root/directory, implying the agent is expected to run with elevated permissions. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection via system log ingestion.
- Ingestion points: The
checkFailedLoginsfunction reads the last 100 lines of/var/log/auth.logor/var/log/syslogviaexecSync. - Boundary markers: None. The content of the logs is processed directly by the script's logic.
- Capability inventory: The script uses
execSyncto run system commands andfsto read/write files in privileged directories. - Sanitization: The script uses regular expressions (
/Failed password|Failed login|Authentication failure/gi) to filter log lines, which provides some protection, but it does not fully sanitize the log data before processing or logging it toalerts.log. - [COMMAND_EXECUTION]: The script
scripts/monitor.cjsutilizeschild_process.execSyncto execute various system commands for monitoring purposes. - Commands executed include
tail,ss,netstat,ps, anddocker ps. - Although these commands are currently hardcoded and do not interpolate user-supplied arguments, the use of
execSyncprovides a powerful capability that could be targeted if the script were modified.
Audit Metadata