hermes-s6-container-supervision
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents the use of administrative commands via
docker execands6-overlayutilities to monitor and manage container processes. These are standard operations for developers managing the container lifecycle. - [DYNAMIC_EXECUTION]: The documentation describes the
ServiceManagerlogic that generates service run scripts at runtime to facilitate profile-based process isolation. This is an internal architectural feature rather than a vulnerability. - [EXTERNAL_DOWNLOADS]: The skill references a technical issue on the official
s6-overlayGitHub repository to explain specific implementation choices regarding container exit codes. This is a reference to a well-known technical resource. - [INDIRECT_PROMPT_INJECTION]: The container boot process involves reading state files (
gateway_state.jsonandSOUL.md) from a persistent volume to restore service status. While this constitutes an ingestion surface for untrusted data, the operation is limited to process state reconciliation and is not exposed to direct external prompt influence.
Audit Metadata