skills/joelhooks/joelclaw/three-body/Gen Agent Trust Hub

three-body

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses SSH to interact with a remote NAS and executes local shell scripts for mount management. These operations are core to the skill's purpose of host-specific management and troubleshooting.
  • [PRIVILEGE_ESCALATION]: The instructions direct the agent to use sudo for specific tasks such as mounting filesystems, installing LaunchDaemons, and modifying network settings. While these are high-privilege actions, they are explicitly scoped to the skill's primary function of infrastructure maintenance.
  • [PERSISTENCE]: The skill manages service persistence through launchd and /Library/LaunchDaemons/ configuration files to ensure NAS mounts are maintained across system reboots.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes output from remote commands (such as dmesg logs and storage status) which serves as an ingestion point for potentially untrusted data.
  • Ingestion points: Output from SSH commands executed on the three-body NAS, as defined in SKILL.md.
  • Boundary markers: None present in the instructions to delimit command output from agent instructions.
  • Capability inventory: SSH command execution, local shell script execution, sudo access, and launchctl service management.
  • Sanitization: None specified for the interpolated command outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — three-body