gentleman-e2e

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill provides Dockerfile patterns that modify the /etc/sudoers file (echo "testuser ALL=(ALL) NOPASSWD:ALL" >> /etc/sudoers) to grant a non-root user full passwordless sudo privileges for testing purposes.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines test logic that reads and parses output from the installation process, which could contain instructions if the installer source is compromised.
  • Ingestion points: Test scripts (e2e_test.sh) read generated configuration files such as .zshrc, config.fish, and Neovim configurations to verify installation success.
  • Boundary markers: None identified in the provided patterns for delimiting external file content during verification.
  • Capability inventory: The skill uses shell command execution (grep, ls, wc), binary execution (gentleman-dots), and file system operations (rm, mkdir).
  • Sanitization: No specific sanitization or escaping is mentioned for processing external configuration data.
  • [COMMAND_EXECUTION]: The skill relies on shell scripts and Docker commands to execute the installer binary and verify system state across multiple platform environments.
  • [EXTERNAL_DOWNLOADS]: The Dockerfile patterns include the installation of standard system dependencies and build tools (git, curl, sudo, build-essential) from official Ubuntu package repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 12:22 AM