skills/djalmajr/skills/aim-ops/Gen Agent Trust Hub

aim-ops

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides shell commands and scripts such as rehearse-upgrade.sh and upgrade-playbook.md that execute high-privilege operations using docker, docker compose, git, and gh to manage the server lifecycle.\n- [DYNAMIC_EXECUTION]: The skill employs dynamic execution in several places: scripts/rehearse-upgrade.sh uses an embedded Python snippet to process JSON configuration; references/compose-stack.md includes a Python script for diagnostic checks; scripts/fix-migration-history.py executes SQL statements dynamically from the filesystem.\n- [EXTERNAL_DOWNLOADS]: The skill pulls Docker images from ghcr.io and docker.io. The ai-memory engine may also download local embedding models if not explicitly configured with a remote provider.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface by ingesting user-supplied configuration values (digests, hostnames, API URLs) which are interpolated into high-privilege command strings and configuration files. This represents a capability surface that processes user-provided data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 07:06 PM
Security Audit — agent-trust-hub — aim-ops