ops-llm
Fail
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill implements a persistence mechanism in
scripts/watchdog.shthat modifies the user'scrontabto execute a check every two minutes. This automated modification of system schedules is high-risk as it ensures the skill's scripts continue to run in the background indefinitely.\n- [COMMAND_EXECUTION]:scripts/cache-clean.shperforms recursive deletion usingrm -rfon directory paths supplied via the--pathargument. The script lacks validation or path-traversal checks, which could allow an attacker to delete arbitrary system files by manipulating the input path.\n- [COMMAND_EXECUTION]: The watchdog and service control scripts use intrusive commands such aspkill -9andsystemctl restart. These operations can cause system-wide disruption and typically require elevated permissions (Privilege Escalation), posing a risk to system stability and security.\n- [COMMAND_EXECUTION]:run.shdynamically sources a.envfile from a relative path (../../../.env) that may reside outside the skill's trusted directory tree. This allows for the potential execution of untrusted configurations if the skill is placed in a nested directory of an untrusted repository.\n- [EXTERNAL_DOWNLOADS]:scripts/model-pull.shfacilitates the download of binary model files from the Ollama registry. While a core function of the skill, it involves fetching and storing large external artifacts from a remote network source.
Recommendations
- AI detected serious security threats
Audit Metadata