ops-embry-agent
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes an installation script (install.sh) using a relative path traversal (../../systemd/install.sh) which targets a directory outside the skill's own root. This pattern leads to the execution of code not contained within the skill's distributed files.- [COMMAND_EXECUTION]: The skill facilitates the installation and activation of a systemd user service (embry-agent.service). This provides a mechanism for persistence where the daemon can run automatically in the background of the user's session.- [COMMAND_EXECUTION]: The skill utilizes powerful system-level utilities including systemctl, journalctl, and busctl to manage services, access system logs, and interact with the D-Bus message bus.- [PROMPT_INJECTION]: The skill contains a surface for indirect prompt injection. 1. Ingestion point: The logs command accepts a user-provided argument for the number of lines to display. 2. Boundary markers: None are used to delimit the input or the resulting log output. 3. Capability inventory: The skill can execute system commands, manage services, and read logs. 4. Sanitization: The input argument is quoted in the script but not explicitly validated as an integer before being passed to system utilities.
Audit Metadata