skills/joelhooks/joelclaw/executor/Gen Agent Trust Hub

executor

Fail

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPERSISTENCECREDENTIALS_UNSAFE
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill explicitly uses administrative privileges via the sudo command to execute deployment scripts such as apply-executor-slice.sh. This is used to install and modify system-wide LaunchDaemons on the host machine.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to perform a git clone of the repository https://github.com/RhysSullivan/executor. This external source is used to inspect upstream source code and verify configuration patterns.
  • [COMMAND_EXECUTION]: The agent is directed to execute numerous system-level commands, including launchctl for service management, lsof for network port monitoring, pgrep for process identification, and curl for performing health checks against local and Tailscale network endpoints.
  • [PERSISTENCE]: The core functionality of the skill involves creating and managing launchd service configurations (com.joelclaw.central.executor), which establishes persistence by ensuring the executor daemon starts automatically during the system boot process.
  • [CREDENTIALS_UNSAFE]: The skill identifies and interacts with a sensitive authentication storage path at /Users/Shared/joelclaw/data/executor/server-control/auth.json. Although the instructions contain explicit warnings against printing or exposing the contents of this file, the skill provides the agent with the exact location of the service's bearer tokens.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — executor