server-md
Warn
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill's primary function is to execute shell commands ('shortcuts') defined in local or remote JSON configuration files. While the skill includes a confirmation code system for high-risk operations to prevent accidental execution, it facilitates arbitrary command execution on the host and remote servers.
- [REMOTE_CODE_EXECUTION]: The synchronization module ('sync') generates Python code as strings and executes them on remote servers via SSH using 'python3 -c'. This pattern involves dynamic script generation and remote execution, which is a significant capability tier for an agent skill.
- [DATA_EXFILTRATION]: The skill facilitates the transfer of server metadata, resource lists, and operational shortcuts between the local machine and remote servers via the 'push' and 'bidir' sync commands. While the CLI tool masks sensitive strings like tokens and IPs in human-readable output, the raw configuration data is exchanged over the network via SSH.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external documentation ('SERVER.md') and configuration files ('server-md.json') which can contain descriptions, warnings, and tips that influence agent decisions. This creates an attack surface where instructions embedded in these data files could be used to manipulate agent behavior. Ingestion points: Reads multiple markdown and JSON files from various locations on the filesystem. Boundary markers: None used to separate data from instructions when presenting record details to the agent. Capability inventory: File writing, subprocess execution (SSH/Shell), and network connectivity. Sanitization: Implements a masking system to redact secrets and network identifiers from the agent's context.
Audit Metadata