system-architecture
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECREDENTIALS_UNSAFEPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The documentation identifies sensitive local file paths, specifically
~/.joelclaw/auth.jsonand~/.joelclaw/capture-auth.db, which are used to store bearer tokens for system authentication. It also provides examples of how to read and use these tokens for authenticated API requests.- [PRIVILEGE_ESCALATION]: The skill contains administrative instructions that utilizesudo, specifically for verifying NAS storage tiers (sudo -u joelclaw -H ./infra/central/scripts/verify-nas.sh) and managing system services.- [COMMAND_EXECUTION]: The skill provides an extensive inventory of shell commands and scripts for system introspection and debugging, includinglaunchctlfor process management,colimafor VM status, andkubectlfor container orchestration.- [INDIRECT_PROMPT_INJECTION]: The architecture described includes multiple ingestion points for untrusted data, such as webhooks, agent-mail services, and satellite machine run captures. This represents a significant attack surface for indirect prompt injection if data entering the system is not properly sanitized before being processed by an agent.- [DYNAMIC_EXECUTION]: The skill defines a detailed "Sandbox Execution Contract" that describes mechanisms for materializing code repositories, executing tasks via Kubernetes Jobs, and managing isolated local sandboxes for agent workloads.
Audit Metadata