system-architecture

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECREDENTIALS_UNSAFEPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The documentation identifies sensitive local file paths, specifically ~/.joelclaw/auth.json and ~/.joelclaw/capture-auth.db, which are used to store bearer tokens for system authentication. It also provides examples of how to read and use these tokens for authenticated API requests.- [PRIVILEGE_ESCALATION]: The skill contains administrative instructions that utilize sudo, specifically for verifying NAS storage tiers (sudo -u joelclaw -H ./infra/central/scripts/verify-nas.sh) and managing system services.- [COMMAND_EXECUTION]: The skill provides an extensive inventory of shell commands and scripts for system introspection and debugging, including launchctl for process management, colima for VM status, and kubectl for container orchestration.- [INDIRECT_PROMPT_INJECTION]: The architecture described includes multiple ingestion points for untrusted data, such as webhooks, agent-mail services, and satellite machine run captures. This represents a significant attack surface for indirect prompt injection if data entering the system is not properly sanitized before being processed by an agent.- [DYNAMIC_EXECUTION]: The skill defines a detailed "Sandbox Execution Contract" that describes mechanisms for materializing code repositories, executing tasks via Kubernetes Jobs, and managing isolated local sandboxes for agent workloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — system-architecture