garage
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates administrative tasks through SSH commands directed at a specific private IP (100.67.156.41). It utilizes tools such as
nc,curl, andsshto monitor and manage the storage service within the user's Tailscale network. - [PRIVILEGE_ESCALATION]: The instructions include the use of
sudofor Docker operations on the ASUSTOR NAS, which is necessary for managing service state and accessing container logs. - [INDIRECT_PROMPT_INJECTION]: The skill captures and processes outputs from network checks and system logs. While this represents a data ingestion point for the agent, the risk is minimal given the private and authenticated nature of the target infrastructure.
- [CREDENTIALS_UNSAFE]: The skill interacts with environment files containing secrets (e.g.,
convex-s3.env). This behavior is explicitly governed by redaction rules within the skill that prevent the AI from revealing raw credential values, ensuring safe handling of sensitive information.
Audit Metadata