ops-embry-agent

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes an installation script (install.sh) using a relative path traversal (../../systemd/install.sh) which targets a directory outside the skill's own root. This pattern leads to the execution of code not contained within the skill's distributed files.- [COMMAND_EXECUTION]: The skill facilitates the installation and activation of a systemd user service (embry-agent.service). This provides a mechanism for persistence where the daemon can run automatically in the background of the user's session.- [COMMAND_EXECUTION]: The skill utilizes powerful system-level utilities including systemctl, journalctl, and busctl to manage services, access system logs, and interact with the D-Bus message bus.- [PROMPT_INJECTION]: The skill contains a surface for indirect prompt injection. 1. Ingestion point: The logs command accepts a user-provided argument for the number of lines to display. 2. Boundary markers: None are used to delimit the input or the resulting log output. 3. Capability inventory: The skill can execute system commands, manage services, and read logs. 4. Sanitization: The input argument is quoted in the script but not explicitly validated as an integer before being passed to system utilities.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:36 AM
Security Audit — agent-trust-hub — ops-embry-agent