Linux Production Shell Scripts

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains templates for executing high-impact commands such as rm -r for backup rotation and find ... -exec rm for data cleanup. These operations are performed on directory paths that are accepted as positional arguments.
  • [PRIVILEGE_ESCALATION]: Several scripts utilize sudo to perform restricted system tasks, including package installation (apt-get install) and service management (systemctl restart). It also includes scripts for administrative user management using useradd and passwd.
  • [PERSISTENCE]: The Task Scheduler (Cron Setup) script provides a mechanism to modify the system crontab, allowing for the execution of scripts that persist across reboots and user sessions.
  • [REMOTE_CODE_EXECUTION]: The Remote Script Execution template uses ssh to pipe a local shell script to a remote server for execution (ssh ... "bash -s" < script.sh).
  • [DATA_EXFILTRATION]: The Remote Server Backup script enables the transfer of local directories to remote servers using rsync over the network.
  • [INDIRECT_PROMPT_INJECTION]: The scripts ingest unvalidated user input via command-line arguments (e.g., server addresses and file paths), creating a vulnerability surface if the agent processes untrusted data.
  • Ingestion points: Positional arguments ($1, $2) in scripts within Phases 4, 5, 8, and 10 of SKILL.md.
  • Boundary markers: No delimiters or instructions to ignore embedded commands are present in the templates.
  • Capability inventory: Includes execution of rm, sudo, rsync, ssh, crontab, and apt-get.
  • Sanitization: The templates do not include logic for input validation, sanitization, or path escaping.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — Linux Production Shell Scripts