dev-capsem-doctor
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- Shell Command Execution: The
run()helper inconftest.pyexecutes commands viasubprocess.run(cmd, shell=True). While intended for running diagnostic tests, using a shell for command execution is a security consideration as it can allow for shell metacharacter injection if command strings are dynamically constructed from untrusted input. - Elevated Privilege Requirement: The
pytest_ignore_collectfunction checks for root privileges (os.geteuid() != 0) and requires write access to the/rootdirectory. The skill is designed to operate with high-level system permissions to verify sandbox integrity and kernel hardening, which is consistent with its purpose as a VM diagnostic suite. - Indirect Prompt Injection Surface: The diagnostic suite is designed to ingest and verify complex data such as database rows, structured logs, and external ledger entries (Ironbank). This represents a potential surface for indirect prompt injection if the agent is directed to process instructions embedded within the data it verifies. (1) Ingestion points: The skill processes external data including the
/ironbankledger, database rows, and structured logs as mentioned in SKILL.md. (2) Boundary markers: There are no explicit delimiters or instructions to ignore embedded content in the provided infrastructure snippets. (3) Capability inventory: The suite possesses capabilities for shell command execution via therunhelper, file system operations including rootfs access, and network connectivity testing. (4) Sanitization: The provided helper functions do not implement explicit sanitization or filtering of the content being verified during the diagnostic process.
Audit Metadata