remote-systems-administration
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a 'Discovery before change' contract, ensuring the agent verifies the target platform and control plane before executing commands.
- [SAFE]: Connectivity-sensitive operations, such as firewall, SSH, and routing changes, are protected by a mandatory safety gate requiring independent recovery paths and tested rollbacks.
- [SAFE]: Data exfiltration risks are mitigated by explicit instructions to redact sensitive information and avoid pasting unbounded logs or configuration files into responses.
- [SAFE]: Fleet automation via Ansible follows best practices, including mandatory canary rollouts, serial batches, and per-host result accounting.
- [SAFE]: The skill strictly enforces host-key verification and prohibits the use of insecure practices such as AutoAddPolicy or disabling host-key checking.
- [SAFE]: Indirect prompt injection risks are addressed by providing clear boundary markers for evidence reporting and guidelines for sanitizing external data processed by the agent.
Audit Metadata