get-available-resources

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/detect_resources.py executes system management tools (nvidia-smi, amd-smi, sysctl, system_profiler) to query hardware state. These operations use subprocess.Popen with shell=False and hardcoded argument lists, preventing shell injection vulnerabilities.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes environmental data which could theoretically be influenced by an attacker. Ingestion points: Data is collected from environment variables and system command output in scripts/detect_resources.py. Boundary markers: The skill enforces a strict JSON schema for all outputs. Capability inventory: Resource probing and restricted local file writing via scripts/_common.py. Sanitization: String inputs are sanitized in scripts/detect_resources.py using _safe_text to remove non-printable characters, enforce length limits (128 characters), and redact sensitive identifiers like hostnames and absolute paths.\n- [DYNAMIC_EXECUTION]: A dynamic import of the psutil library is performed in scripts/detect_resources.py using a hardcoded string. This is a legitimate optional dependency for enhanced system telemetry.\n- [PRIVILEGE_ESCALATION]: File writing in scripts/_common.py implements significant defensive measures, including path restriction to the current directory, rejection of symbolic links, and enforcement of private file permissions (mode 0o600).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — get-available-resources