autonomous-vps

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow where the agent ingests data from external GitHub repositories while maintaining high-privilege access to a VPS via an admin container and Docker socket. This combination creates a surface for indirect prompt injection.\n- Ingestion points: Repository clones from GitHub (Step 1).\n- Boundary markers: The skill mentions behavioral guards (CLAUDE.md) and requires human confirmation for destructive actions, which mitigate but do not eliminate the risk.\n- Capability inventory: The agent has broad control over Docker, services, and the file system (Step 3).\n- Sanitization: No explicit content sanitization or validation rules are defined for data read from the repositories.\n- [SAFE]: The skill is entirely instructional and does not include any executable code, binary files, or external package dependencies.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: Credential management follows best practices, instructing the agent to work with secret references rather than plaintext values and prohibiting their inclusion in responses.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 08:14 PM
Security Audit — agent-trust-hub — autonomous-vps