ops-claude

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The run.sh script utilizes sudo to perform administrative tasks, specifically modifying system kernel parameters via sysctl and updating the /etc/sysctl.conf configuration file to increase inotify limits.
  • [COMMAND_EXECUTION]: The skill modifies user shell environment files (.zshrc, .bashrc) by appending environment variables (NODE_OPTIONS) to optimize Node.js heap size.
  • [COMMAND_EXECUTION]: The run.sh script executes recursive directory removals (rm -rf) on various cache and environment directories identified through find operations on the local filesystem.
  • [REMOTE_CODE_EXECUTION]: The sanity.sh script employs eval for command execution during health check routines, which can be a vector for executing arbitrary code if command strings are manipulated.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing data from the external ccusage CLI tool. 1. Ingestion points: Output from ccusage processed in usage.py. 2. Boundary markers: None identified. 3. Capability inventory: run.sh performs high-privilege system modifications and file deletions. 4. Sanitization: Basic JSON parsing is performed, but no domain-specific validation of usage metrics is present.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — ops-claude