minio
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous instructions for the agent to execute shell commands via SSH on a remote NAS (
three-body). These include management of Docker containers, checking service health withcurlandnc, and running maintenance scripts. - [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read and process external data, creating an attack surface for indirect prompt injection.
- Ingestion points: Tool output from
docker compose logs, MinIO bucket listings (mc ls), and object content inspection (mc cat). - Boundary markers: None explicitly defined for input data, though the skill provides instructions to the agent to scan and redact its own output.
- Capability inventory: Remote command execution via SSH, container management with
sudo docker, network operations (curl,nc), and file operations in S3 buckets (mc cp,mc rm). - Sanitization: The skill provides specific patterns for redacting AWS and MinIO credentials from command outputs using
awkand manual scanning before reporting to the user.
Audit Metadata