linux-archive-integrity
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute powerful system commands including
tar,gpg, andsha256sumwithsudoprivileges to manage system-level archives in directories like/etcand/var/www.- [CREDENTIALS_UNSAFE]: The documentation references the sensitive file path~/.backup-encryption-keyfor storing GPG symmetric passphrases. While it provides guidance on key hygiene, this path represents a potential target for credential access.- [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface by ingesting data from the host filesystem into the agent's context during archive creation and verification. - Ingestion points: Files and directory trees from the local filesystem (e.g.,
/var/www,/etc) are read by thetarcommand. - Boundary markers: The instructions do not specify explicit boundary markers or sanitization for the content of the files being processed.
- Capability inventory: The skill utilizes
tarfor filesystem reads/writes,sha256sumfor integrity checks, andgpgfor encryption/signing, all of which may be run withsudoelevation. - Sanitization: There is no evidence of sanitization or filtering of the file content before it is processed or reported by the agent.
Audit Metadata