skills/joelhooks/joelclaw/garage/Gen Agent Trust Hub

garage

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates administrative tasks through SSH commands directed at a specific private IP (100.67.156.41). It utilizes tools such as nc, curl, and ssh to monitor and manage the storage service within the user's Tailscale network.
  • [PRIVILEGE_ESCALATION]: The instructions include the use of sudo for Docker operations on the ASUSTOR NAS, which is necessary for managing service state and accessing container logs.
  • [INDIRECT_PROMPT_INJECTION]: The skill captures and processes outputs from network checks and system logs. While this represents a data ingestion point for the agent, the risk is minimal given the private and authenticated nature of the target infrastructure.
  • [CREDENTIALS_UNSAFE]: The skill interacts with environment files containing secrets (e.g., convex-s3.env). This behavior is explicitly governed by redaction rules within the skill that prevent the AI from revealing raw credential values, ensuring safe handling of sensitive information.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — garage