autonomous-vps
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow where the agent ingests data from external GitHub repositories while maintaining high-privilege access to a VPS via an admin container and Docker socket. This combination creates a surface for indirect prompt injection.\n- Ingestion points: Repository clones from GitHub (Step 1).\n- Boundary markers: The skill mentions behavioral guards (CLAUDE.md) and requires human confirmation for destructive actions, which mitigate but do not eliminate the risk.\n- Capability inventory: The agent has broad control over Docker, services, and the file system (Step 3).\n- Sanitization: No explicit content sanitization or validation rules are defined for data read from the repositories.\n- [SAFE]: The skill is entirely instructional and does not include any executable code, binary files, or external package dependencies.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: Credential management follows best practices, instructing the agent to work with secret references rather than plaintext values and prohibiting their inclusion in responses.
Audit Metadata