sre-engineer

Warn

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains scripts that execute high-privilege system commands across multiple files.
  • Evidence: Use of iptables for network partitioning and tc (traffic control) for latency injection in references/incident-chaos.md.
  • Evidence: Use of systemctl restart and kubectl delete for automated remediation in references/automation-toil.md.
  • Evidence: The AutomatedRunbook class in references/automation-toil.md executes command strings using subprocess.run with shell=True, which is a risky pattern that can lead to command injection if input is not strictly controlled.
  • [EXTERNAL_DOWNLOADS]: The skill relies on external libraries that are not part of the standard Python distribution.
  • Evidence: Import of the numpy library in references/automation-toil.md for capacity planning calculations.
  • Evidence: Import of the grafana_dashboard library in references/monitoring-alerting.md for dashboard generation.
  • [PROMPT_INJECTION]: The skill implements an automated decision-making loop based on external data, creating a surface for indirect prompt injection.
  • Ingestion points: The get_error_rate function in SKILL.md fetches and parses JSON data from a remote Prometheus API (http://prometheus:9090).
  • Boundary markers: No specific delimiters or warnings are used to instruct the agent to ignore potentially malicious content within the monitoring data.
  • Capability inventory: The skill possesses extensive system-level capabilities, including the ability to restart deployments (kubectl rollout restart) and modify network rules.
  • Sanitization: The skill lacks sanitization or integrity verification for the data retrieved from the monitoring API before using it to trigger operational actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 08:51 PM
Security Audit — agent-trust-hub — sre-engineer