Linux Production Shell Scripts
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains templates for executing high-impact commands such as
rm -rfor backup rotation andfind ... -exec rmfor data cleanup. These operations are performed on directory paths that are accepted as positional arguments. - [PRIVILEGE_ESCALATION]: Several scripts utilize
sudoto perform restricted system tasks, including package installation (apt-get install) and service management (systemctl restart). It also includes scripts for administrative user management usinguseraddandpasswd. - [PERSISTENCE]: The
Task Scheduler (Cron Setup)script provides a mechanism to modify the systemcrontab, allowing for the execution of scripts that persist across reboots and user sessions. - [REMOTE_CODE_EXECUTION]: The
Remote Script Executiontemplate usessshto pipe a local shell script to a remote server for execution (ssh ... "bash -s" < script.sh). - [DATA_EXFILTRATION]: The
Remote Server Backupscript enables the transfer of local directories to remote servers usingrsyncover the network. - [INDIRECT_PROMPT_INJECTION]: The scripts ingest unvalidated user input via command-line arguments (e.g., server addresses and file paths), creating a vulnerability surface if the agent processes untrusted data.
- Ingestion points: Positional arguments ($1, $2) in scripts within Phases 4, 5, 8, and 10 of
SKILL.md. - Boundary markers: No delimiters or instructions to ignore embedded commands are present in the templates.
- Capability inventory: Includes execution of
rm,sudo,rsync,ssh,crontab, andapt-get. - Sanitization: The templates do not include logic for input validation, sanitization, or path escaping.
Audit Metadata