dev-capsem-doctor

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Shell Command Execution: The run() helper in conftest.py executes commands via subprocess.run(cmd, shell=True). While intended for running diagnostic tests, using a shell for command execution is a security consideration as it can allow for shell metacharacter injection if command strings are dynamically constructed from untrusted input.
  • Elevated Privilege Requirement: The pytest_ignore_collect function checks for root privileges (os.geteuid() != 0) and requires write access to the /root directory. The skill is designed to operate with high-level system permissions to verify sandbox integrity and kernel hardening, which is consistent with its purpose as a VM diagnostic suite.
  • Indirect Prompt Injection Surface: The diagnostic suite is designed to ingest and verify complex data such as database rows, structured logs, and external ledger entries (Ironbank). This represents a potential surface for indirect prompt injection if the agent is directed to process instructions embedded within the data it verifies. (1) Ingestion points: The skill processes external data including the /ironbank ledger, database rows, and structured logs as mentioned in SKILL.md. (2) Boundary markers: There are no explicit delimiters or instructions to ignore embedded content in the provided infrastructure snippets. (3) Capability inventory: The suite possesses capabilities for shell command execution via the run helper, file system operations including rootfs access, and network connectivity testing. (4) Sanitization: The provided helper functions do not implement explicit sanitization or filtering of the content being verified during the diagnostic process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:45 PM
Security Audit — agent-trust-hub — dev-capsem-doctor