linuxmirrors-os

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional, focusing on guiding the agent to generate system configuration plans rather than executing commands automatically. This approach maintains human-in-the-loop safety for sensitive OS operations.
  • [SAFE]: The documentation contains explicit security warnings against dangerous patterns, such as piping remote scripts directly into a shell (curl | bash), recommending instead that users download and audit scripts locally before execution.
  • [SAFE]: Comprehensive operational guardrails are provided in the references/ directory, including a pre-flight checklist for environmental verification and a dedicated rollback guide to ensure system recoverability.
  • [PROMPT_INJECTION]: The instructions do not contain any attempts to override model safety filters, switch to unrestricted modes, or bypass platform constraints. The rules are focused on maintaining accuracy and safety in mirror management.
  • [DATA_EXFILTRATION]: No network exfiltration or sensitive file access patterns were detected. The skill correctly handles the requirement for administrative privileges as a necessary component of the task without abusing access to harvesting credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes a self-referential HTML report (evaluation-report.html) containing safety claims (e.g., "Official: Pass"). While these are treated as data rather than authoritative safety conclusions per analysis rules, they are presented as a static report and do not contain hidden instructions or malicious payloads designed to influence agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:14 AM
Security Audit — agent-trust-hub — linuxmirrors-os