ops-claude
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
run.shscript utilizessudoto perform administrative tasks, specifically modifying system kernel parameters viasysctland updating the/etc/sysctl.confconfiguration file to increase inotify limits. - [COMMAND_EXECUTION]: The skill modifies user shell environment files (
.zshrc,.bashrc) by appending environment variables (NODE_OPTIONS) to optimize Node.js heap size. - [COMMAND_EXECUTION]: The
run.shscript executes recursive directory removals (rm -rf) on various cache and environment directories identified throughfindoperations on the local filesystem. - [REMOTE_CODE_EXECUTION]: The
sanity.shscript employsevalfor command execution during health check routines, which can be a vector for executing arbitrary code if command strings are manipulated. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing data from the external
ccusageCLI tool. 1. Ingestion points: Output fromccusageprocessed inusage.py. 2. Boundary markers: None identified. 3. Capability inventory:run.shperforms high-privilege system modifications and file deletions. 4. Sanitization: Basic JSON parsing is performed, but no domain-specific validation of usage metrics is present.
Audit Metadata