ops-llm

Fail

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill implements a persistence mechanism in scripts/watchdog.sh that modifies the user's crontab to execute a check every two minutes. This automated modification of system schedules is high-risk as it ensures the skill's scripts continue to run in the background indefinitely.\n- [COMMAND_EXECUTION]: scripts/cache-clean.sh performs recursive deletion using rm -rf on directory paths supplied via the --path argument. The script lacks validation or path-traversal checks, which could allow an attacker to delete arbitrary system files by manipulating the input path.\n- [COMMAND_EXECUTION]: The watchdog and service control scripts use intrusive commands such as pkill -9 and systemctl restart. These operations can cause system-wide disruption and typically require elevated permissions (Privilege Escalation), posing a risk to system stability and security.\n- [COMMAND_EXECUTION]: run.sh dynamically sources a .env file from a relative path (../../../.env) that may reside outside the skill's trusted directory tree. This allows for the potential execution of untrusted configurations if the skill is placed in a nested directory of an untrusted repository.\n- [EXTERNAL_DOWNLOADS]: scripts/model-pull.sh facilitates the download of binary model files from the Ollama registry. While a core function of the skill, it involves fetching and storing large external artifacts from a remote network source.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — ops-llm