chaos-engineering-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides scripts and examples that utilize system commands for chaos engineering purposes, such as invoking the tc (traffic control) utility for network latency simulation and the gremlin CLI for resource exhaustion attacks.
  • [DYNAMIC_EXECUTION]: The custom failure injection logic in Python uses subprocess.run and the multiprocessing module to dynamically create system-level failures and stress CPU/memory resources at runtime.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to ingest data from user-defined external health endpoints to verify system state, which constitutes a potential injection surface for untrusted external data.
  • Ingestion points: references/EXAMPLES.md (verify_steady_state method within the ChaosInjector class).
  • Boundary markers: Absent; there are no specific delimiters or instructions to ignore embedded instructions in the ingested JSON health data.
  • Capability inventory: subprocess.run (system command execution), psutil.kill (process termination), and requests.get (network access).
  • Sanitization: Absent; the verification logic directly processes JSON responses from the target service without additional validation or filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — chaos-engineering-expert