opnsense-pfsense

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses various FreeBSD-specific commands for firewall management, including pfctl for rule manipulation, configctl for OPNsense service management, and pfSsh.php for pfSense operations. These are appropriate for the skill's administrative purpose.
  • [EXTERNAL_DOWNLOADS]: The instructions reference external sources for security updates and migration tools. This includes the cscli hub command for CrowdSec scenario updates and links to third-party GitHub repositories (meyergru/iscdhcp_to_dnsmasq and dreary-ennui/Convert-OPNSenseISCDHCPtoDNSMasqDHCP) for DHCP migration assistance. These references are provided for user-directed tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves the agent reading and analyzing log files such as /var/log/filter.log, eve.json, and CrowdSec alert logs. This ingestion of potentially untrusted data represents an indirect prompt injection surface.
  • Ingestion points: System, firewall, and security plugin log files mentioned in SKILL.md and references/plugins.md.
  • Boundary markers: No specific delimiters or instructions to ignore instructions within logs are provided in the skill text.
  • Capability inventory: The skill environment allows for administrative shell commands and firewall configuration changes.
  • Sanitization: There are no instructions for sanitizing or filtering log content before processing by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 02:03 AM
Security Audit — agent-trust-hub — opnsense-pfsense