homelab-pihole-dns
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches installation scripts, binaries, and configuration lists from established project sites and trusted organizations.
- Downloads the official Pi-hole installer from
install.pi-hole.net. - Fetches the
cloudflaredbinary from the official releases on Cloudflare's GitHub repository. - References third-party blocklists hosted on GitHub (e.g.,
StevenBlack/hosts). - [REMOTE_CODE_EXECUTION]: Provides instructions to download and execute the official Pi-hole installation script. The skill includes specific security guidance to inspect the script (
less pi-hole-install.sh) and verify checksums/signatures for binaries before execution. - [COMMAND_EXECUTION]: Utilizes standard system utilities and project-specific CLI tools (e.g.,
curl,systemctl,pihole) to manage network services and configuration files. - [PRIVILEGE_ESCALATION]: Employs
sudofor administrative tasks such as installing system services, managing binaries in/usr/local/bin, and modifying network configuration files (e.g.,/etc/dhcpcd.conf). This level of access is necessary for the intended purpose of managing a DNS and DHCP server. - [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to help users add external adlists, which could theoretically contain malicious content if a source is compromised.
- Ingestion points: External blocklist URLs referenced in the adlist management section of
SKILL.md. - Boundary markers: Absent; the data is expected to be in standard host-file format.
- Capability inventory: The skill uses
curl,bash, andsudofor system management tasks as defined inSKILL.md. - Sanitization: None; the external content is processed as domain lists by the Pi-hole application.
Audit Metadata