enclave-inspect

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Provides instructions to execute shell commands within enclave services using kurtosis service exec. It also includes destructive lifecycle commands such as kurtosis enclave rm and kurtosis clean -a for resource management.
  • [DATA_EXFILTRATION]: Supports exporting enclave state, including logs, configurations, and file artifacts, to the local filesystem via the kurtosis enclave dump command.
  • [PROMPT_INJECTION]: Contains a potential surface for indirect prompt injection as the agent is instructed to read service logs and file artifacts which originate from untrusted enclave processes.
  • Ingestion points: Service logs and file artifacts retrieved via kurtosis service logs and kurtosis enclave inspect (found in SKILL.md).
  • Boundary markers: Absent; there are no specific instructions for the agent to ignore or delimit instructions found within service outputs.
  • Capability inventory: The skill possesses executive capabilities (kurtosis service exec) and destructive management capabilities (kurtosis clean -a).
  • Sanitization: None; the skill assumes the output from the kurtosis CLI is safe to process directly.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 12:40 PM
Security Audit — agent-trust-hub — enclave-inspect