linux-archive-integrity

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute powerful system commands including tar, gpg, and sha256sum with sudo privileges to manage system-level archives in directories like /etc and /var/www.- [CREDENTIALS_UNSAFE]: The documentation references the sensitive file path ~/.backup-encryption-key for storing GPG symmetric passphrases. While it provides guidance on key hygiene, this path represents a potential target for credential access.- [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface by ingesting data from the host filesystem into the agent's context during archive creation and verification.
  • Ingestion points: Files and directory trees from the local filesystem (e.g., /var/www, /etc) are read by the tar command.
  • Boundary markers: The instructions do not specify explicit boundary markers or sanitization for the content of the files being processed.
  • Capability inventory: The skill utilizes tar for filesystem reads/writes, sha256sum for integrity checks, and gpg for encryption/signing, all of which may be run with sudo elevation.
  • Sanitization: There is no evidence of sanitization or filtering of the file content before it is processed or reported by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:40 AM