three-body
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses SSH to interact with a remote NAS and executes local shell scripts for mount management. These operations are core to the skill's purpose of host-specific management and troubleshooting.
- [PRIVILEGE_ESCALATION]: The instructions direct the agent to use
sudofor specific tasks such as mounting filesystems, installing LaunchDaemons, and modifying network settings. While these are high-privilege actions, they are explicitly scoped to the skill's primary function of infrastructure maintenance. - [PERSISTENCE]: The skill manages service persistence through
launchdand/Library/LaunchDaemons/configuration files to ensure NAS mounts are maintained across system reboots. - [INDIRECT_PROMPT_INJECTION]: The skill processes output from remote commands (such as
dmesglogs and storage status) which serves as an ingestion point for potentially untrusted data. - Ingestion points: Output from SSH commands executed on the
three-bodyNAS, as defined inSKILL.md. - Boundary markers: None present in the instructions to delimit command output from agent instructions.
- Capability inventory: SSH command execution, local shell script execution,
sudoaccess, andlaunchctlservice management. - Sanitization: None specified for the interpolated command outputs.
Audit Metadata