security-monitor

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEDATA_EXFILTRATIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXPOSURE_EXFILTRATION]: The script scripts/monitor.cjs accesses sensitive file paths and directories normally restricted to root users.
  • It checks for modifications and credential presence in /root/clawd/.env, /root/clawd/skills/.env, and /root/clawd/config.
  • While the script currently only logs the presence of specific API service keywords (e.g., 'TWITTER', 'KAPSO') and file modification timestamps rather than the secret values themselves, the capability to read these files constitutes a data exposure risk.
  • [PRIVILEGE_ESCALATION]: The skill requires high-level system privileges to operate correctly, as seen in scripts/monitor.cjs.
  • The checkFailedLogins function attempts to read /var/log/auth.log and /var/log/syslog, which are typically only readable by root or members of the adm group.
  • The script monitors files within the /root/ directory, implying the agent is expected to run with elevated permissions.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection via system log ingestion.
  • Ingestion points: The checkFailedLogins function reads the last 100 lines of /var/log/auth.log or /var/log/syslog via execSync.
  • Boundary markers: None. The content of the logs is processed directly by the script's logic.
  • Capability inventory: The script uses execSync to run system commands and fs to read/write files in privileged directories.
  • Sanitization: The script uses regular expressions (/Failed password|Failed login|Authentication failure/gi) to filter log lines, which provides some protection, but it does not fully sanitize the log data before processing or logging it to alerts.log.
  • [COMMAND_EXECUTION]: The script scripts/monitor.cjs utilizes child_process.execSync to execute various system commands for monitoring purposes.
  • Commands executed include tail, ss, netstat, ps, and docker ps.
  • Although these commands are currently hardcoded and do not interpolate user-supplied arguments, the use of execSync provides a powerful capability that could be targeted if the script were modified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — security-monitor