skills/iuliandita/skills/nixos/Gen Agent Trust Hub

nixos

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references several remote repositories and installers including nix-community (disko, home-manager, nixos-anywhere), Mic92/sops-nix, and ryantm/agenix. These are well-known and reputable projects within the Nix ecosystem. Additionally, it references Determinate Systems and the official NixOS channels, which are established and trusted entities.
  • [COMMAND_EXECUTION]: The skill provides numerous administrative commands for system management, including nixos-rebuild, nix-collect-garbage, and disk formatting via disko. These are appropriate for the skill's stated purpose of NixOS administration. The skill includes explicit warnings for high-risk operations like the dd command for writing images to disks.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes external data including system logs via journalctl and configuration files that could potentially contain untrusted input. This represents a standard administrative attack surface.
  • Ingestion points: System logs (journalctl), Nix configuration files (flake.nix, configuration.nix), and bootloader entries.
  • Boundary markers: None explicitly defined for isolating processed data from agent instructions.
  • Capability inventory: The agent has high-privilege access to execute system-wide configuration changes, manage secrets, and format disks.
  • Sanitization: No explicit sanitization or filtering of log data or configuration content is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 09:56 AM
Security Audit — agent-trust-hub — nixos