openhands-enterprise-troubleshooting
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the execution of various diagnostic commands using kubectl and openssl to monitor pod health, verify service readiness, and inspect system logs.
- [PRIVILEGE_ESCALATION]: The diagnostic workflow utilizes sudo for specific administrative tasks, such as generating support bundles and accessing the embedded k0s cluster controller, which is necessary for managing the VM-based enterprise environment.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from log files and support bundles for analysis. The evidence chain includes ingestion points in the SKILL.md and support-bundle-analysis.md files, capability inventory involving kubectl and file read operations, and absence of automated sanitization for raw log excerpts, although manual review and interpretation guidelines are provided.
Audit Metadata