ops-workstation

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes various system utilities to perform diagnostics and maintenance. Key scripts like hogs.sh and vscode.sh utilize the ps command to monitor process activity and kill to terminate runaway workers. The health.sh script uses smartctl to retrieve drive SMART data, which is an expected operation for hardware monitoring. These commands are gated by user-invoked flags like --fix or require explicit sudo privileges as noted in the documentation.\n- [EXTERNAL_DOWNLOADS]: The net.sh script performs network connectivity checks by pinging well-known public DNS services, specifically Cloudflare (1.1.1.1) and Google (8.8.8.8). It also attempts to resolve github.com using getent hosts. These operations target established, well-known services and are standard practice for verifying internet access.\n- [PROMPT_INJECTION]: The skill processes system logs via journalctl and process information via ps. This creates an attack surface for indirect prompt injection if an attacker were to place malicious instructions in log messages or process names. However, the skill does not contain any instructions to override safety filters, and the analysis of the scripts found no evidence of malicious intent or behavior influenced by these logs.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — ops-workstation