chaos-engineering-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides scripts and examples that utilize system commands for chaos engineering purposes, such as invoking the
tc(traffic control) utility for network latency simulation and thegremlinCLI for resource exhaustion attacks. - [DYNAMIC_EXECUTION]: The custom failure injection logic in Python uses
subprocess.runand themultiprocessingmodule to dynamically create system-level failures and stress CPU/memory resources at runtime. - [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to ingest data from user-defined external health endpoints to verify system state, which constitutes a potential injection surface for untrusted external data.
- Ingestion points:
references/EXAMPLES.md(verify_steady_statemethod within theChaosInjectorclass). - Boundary markers: Absent; there are no specific delimiters or instructions to ignore embedded instructions in the ingested JSON health data.
- Capability inventory:
subprocess.run(system command execution),psutil.kill(process termination), andrequests.get(network access). - Sanitization: Absent; the verification logic directly processes JSON responses from the target service without additional validation or filtering.
Audit Metadata