get-available-resources
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/detect_resources.pyexecutes system management tools (nvidia-smi,amd-smi,sysctl,system_profiler) to query hardware state. These operations usesubprocess.Popenwithshell=Falseand hardcoded argument lists, preventing shell injection vulnerabilities.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes environmental data which could theoretically be influenced by an attacker. Ingestion points: Data is collected from environment variables and system command output inscripts/detect_resources.py. Boundary markers: The skill enforces a strict JSON schema for all outputs. Capability inventory: Resource probing and restricted local file writing viascripts/_common.py. Sanitization: String inputs are sanitized inscripts/detect_resources.pyusing_safe_textto remove non-printable characters, enforce length limits (128 characters), and redact sensitive identifiers like hostnames and absolute paths.\n- [DYNAMIC_EXECUTION]: A dynamic import of thepsutillibrary is performed inscripts/detect_resources.pyusing a hardcoded string. This is a legitimate optional dependency for enhanced system telemetry.\n- [PRIVILEGE_ESCALATION]: File writing inscripts/_common.pyimplements significant defensive measures, including path restriction to the current directory, rejection of symbolic links, and enforcement of private file permissions (mode0o600).
Audit Metadata