tailnet-multi-machine
Warn
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides explicit instructions and templates for the agent to execute shell commands on multiple remote machines via SSH, effectively extending the agent's execution environment across the network.
- [COMMAND_EXECUTION]: Relies heavily on high-privilege shell tools including ssh, scp, rsync, and systemctl to manage system configurations and services. The directive to 'not ask the user to do it manually' increases the risk of unauthorized or unintended system changes.
- [PERSISTENCE]: Instructs the agent on how to maintain long-running processes on remote machines by creating systemd user services and using the loginctl enable-linger command, which allows code to run even after the agent session ends.
- [PRIVILEGE_ESCALATION]: Recommends lowering SSH security standards by using StrictHostKeyChecking=accept-new, which allows the agent to connect to potentially untrusted hosts without verifying their identity, increasing the risk of man-in-the-middle attacks.
- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to processing malicious data from untrusted sources.
- Ingestion points: The agent reads files from remote machines via SSH cat commands.
- Boundary markers: Absent; there are no delimiters or warnings to prevent the agent from following instructions found within remote files.
- Capability inventory: The agent possesses broad capabilities including remote command execution, file system modification, and package installation across several workstations and servers.
- Sanitization: Absent; no logic is provided to filter or validate content retrieved from remote files before processing.
Audit Metadata