executor
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: HIGHPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPERSISTENCECREDENTIALS_UNSAFE
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill explicitly uses administrative privileges via the
sudocommand to execute deployment scripts such asapply-executor-slice.sh. This is used to install and modify system-wide LaunchDaemons on the host machine. - [EXTERNAL_DOWNLOADS]: The skill instructs the agent to perform a
git cloneof the repositoryhttps://github.com/RhysSullivan/executor. This external source is used to inspect upstream source code and verify configuration patterns. - [COMMAND_EXECUTION]: The agent is directed to execute numerous system-level commands, including
launchctlfor service management,lsoffor network port monitoring,pgrepfor process identification, andcurlfor performing health checks against local and Tailscale network endpoints. - [PERSISTENCE]: The core functionality of the skill involves creating and managing
launchdservice configurations (com.joelclaw.central.executor), which establishes persistence by ensuring the executor daemon starts automatically during the system boot process. - [CREDENTIALS_UNSAFE]: The skill identifies and interacts with a sensitive authentication storage path at
/Users/Shared/joelclaw/data/executor/server-control/auth.json. Although the instructions contain explicit warnings against printing or exposing the contents of this file, the skill provides the agent with the exact location of the service's bearer tokens.
Recommendations
- AI detected serious security threats
Audit Metadata