monitor-ollama

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/check.sh performs several low-level system operations including process monitoring with pgrep, service management via systemctl restart ollama, and process termination using pkill -9 -x ollama. These actions are functionally necessary for a watchdog service but represent high-privilege system interactions.
  • [COMMAND_EXECUTION]: The scripts/install-cron.sh and scripts/uninstall-cron.sh scripts modify the user's crontab to establish automated execution every two minutes. While documented as the primary persistence mechanism for the watchdog, modifying crontabs is a standard persistence technique used to maintain access across sessions.
  • [SAFE]: The network operations performed in scripts/check.sh via curl target the local Ollama API (defaulting to 127.0.0.1). These operations are limited to health checks (/api/tags and /api/chat) and do not involve data exfiltration to external domains.
  • [SAFE]: The test fixture fixtures/agentic_eval.json references a validation script from a separate project directory (../../best-practices-skills/scripts/validate_skill.py). This is a typical local development testing pattern and does not involve remote code execution or untrusted downloads.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — monitor-ollama