gateway-setup
Warn
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: MEDIUMPERSISTENCECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PERSISTENCE]: The skill is designed to facilitate the creation of a persistent gateway for AI agents on macOS, involving the setup of embedded daemons and watchdog processes to ensure the agent remains "always on."
- [COMMAND_EXECUTION]: The instructions direct the agent to utilize a "repository installer" and perform health checks, which involve executing system commands to manage pollers, socket listeners, and service configurations.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external configuration data from
gatewayand service ownership files to determine setup parameters, creating an ingestion surface for potentially untrusted content. - Ingestion points: Reads
gatewayand existing service ownership configuration files. - Boundary markers: The skill does not explicitly define delimiters or "ignore" instructions for the content of these configuration files.
- Capability inventory: Includes the ability to execute an installer, configure daemons, and set up network adapters/listeners.
- Sanitization: Instructions recommend verifying credentials via a "secret mechanism" to avoid exposing them in logs or files, though no explicit sanitization of configuration text is mentioned.
Audit Metadata