sre-engineer

Fail

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides Python templates and examples that execute high-privilege system commands using the subprocess module. Examples include systemctl restart for service management, find ... -delete for file system operations, and various kubectl commands for container orchestration.
  • [COMMAND_EXECUTION]: Chaos engineering scripts in references/incident-chaos.md utilize tc (traffic control) to inject network latency and iptables to create network partitions, requiring root-level capabilities.
  • [REMOTE_CODE_EXECUTION]: The AutomatedRunbook class in references/automation-toil.md performs unsafe command execution using subprocess.run(step.command, shell=True). This implementation lacks input sanitization and could allow arbitrary code execution if the runbook steps are generated from untrusted data or user input.
  • [EXTERNAL_DOWNLOADS]: Automation logic is driven by data fetched from external network endpoints, such as http://prometheus:9090 in SKILL.md and http://localhost:8080/health in references/automation-toil.md, which could be exploited through server-side request forgery (SSRF) or data poisoning to trigger unintended system actions.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection where malicious instructions could be embedded in the data processed by the agent to influence execution of privileged commands.
  • Ingestion points: Internal Prometheus API (SKILL.md), local health endpoints (references/automation-toil.md), and potentially service logs or incident reports.
  • Boundary markers: None identified; there are no instructions to the agent to delimit or ignore instructions embedded in the external metric data or logs.
  • Capability inventory: High-privilege access to kubectl, systemctl, iptables, and tc via shell execution.
  • Sanitization: Absence of shell argument validation or sanitization in the provided automation templates.
Recommendations
  • HIGH: Downloads and executes remote code from: http://prometheus:9090/api/v1/query?query={urllib.request.quote(query)} - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — sre-engineer