aim-ops
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides shell commands and scripts such as
rehearse-upgrade.shandupgrade-playbook.mdthat execute high-privilege operations usingdocker,docker compose,git, andghto manage the server lifecycle.\n- [DYNAMIC_EXECUTION]: The skill employs dynamic execution in several places:scripts/rehearse-upgrade.shuses an embedded Python snippet to process JSON configuration;references/compose-stack.mdincludes a Python script for diagnostic checks;scripts/fix-migration-history.pyexecutes SQL statements dynamically from the filesystem.\n- [EXTERNAL_DOWNLOADS]: The skill pulls Docker images fromghcr.ioanddocker.io. Theai-memoryengine may also download local embedding models if not explicitly configured with a remote provider.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface by ingesting user-supplied configuration values (digests, hostnames, API URLs) which are interpolated into high-privilege command strings and configuration files. This represents a capability surface that processes user-provided data.
Audit Metadata