enclave-inspect
Pass
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Provides instructions to execute shell commands within enclave services using
kurtosis service exec. It also includes destructive lifecycle commands such askurtosis enclave rmandkurtosis clean -afor resource management. - [DATA_EXFILTRATION]: Supports exporting enclave state, including logs, configurations, and file artifacts, to the local filesystem via the
kurtosis enclave dumpcommand. - [PROMPT_INJECTION]: Contains a potential surface for indirect prompt injection as the agent is instructed to read service logs and file artifacts which originate from untrusted enclave processes.
- Ingestion points: Service logs and file artifacts retrieved via
kurtosis service logsandkurtosis enclave inspect(found in SKILL.md). - Boundary markers: Absent; there are no specific instructions for the agent to ignore or delimit instructions found within service outputs.
- Capability inventory: The skill possesses executive capabilities (
kurtosis service exec) and destructive management capabilities (kurtosis clean -a). - Sanitization: None; the skill assumes the output from the
kurtosisCLI is safe to process directly.
Audit Metadata