sre-engineer
Warn
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains scripts that execute high-privilege system commands across multiple files.
- Evidence: Use of
iptablesfor network partitioning andtc(traffic control) for latency injection inreferences/incident-chaos.md. - Evidence: Use of
systemctl restartandkubectl deletefor automated remediation inreferences/automation-toil.md. - Evidence: The
AutomatedRunbookclass inreferences/automation-toil.mdexecutes command strings usingsubprocess.runwithshell=True, which is a risky pattern that can lead to command injection if input is not strictly controlled. - [EXTERNAL_DOWNLOADS]: The skill relies on external libraries that are not part of the standard Python distribution.
- Evidence: Import of the
numpylibrary inreferences/automation-toil.mdfor capacity planning calculations. - Evidence: Import of the
grafana_dashboardlibrary inreferences/monitoring-alerting.mdfor dashboard generation. - [PROMPT_INJECTION]: The skill implements an automated decision-making loop based on external data, creating a surface for indirect prompt injection.
- Ingestion points: The
get_error_ratefunction inSKILL.mdfetches and parses JSON data from a remote Prometheus API (http://prometheus:9090). - Boundary markers: No specific delimiters or warnings are used to instruct the agent to ignore potentially malicious content within the monitoring data.
- Capability inventory: The skill possesses extensive system-level capabilities, including the ability to restart deployments (
kubectl rollout restart) and modify network rules. - Sanitization: The skill lacks sanitization or integrity verification for the data retrieved from the monitoring API before using it to trigger operational actions.
Audit Metadata