linux-cloud-init

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions and documentation recommend downloading configuration files and bootstrap scripts from the author's GitHub repository (github.com/petebwire/linux-skills.git). It also references official repositories for well-known services including Docker (download.docker.com) and NodeSource (deb.nodesource.com).
  • [REMOTE_CODE_EXECUTION]: Documentation and worked examples provide instructions for the agent to download and execute shell scripts (e.g., setup-claude-code.sh and install-skills-bin) with elevated privileges (sudo bash) on the systems being provisioned.
  • [COMMAND_EXECUTION]: The skill workflow involves executing shell commands to validate, debug, and test configurations, including the use of 'lxc exec' to interact with test containers and 'cloud-init' system tools to analyze boot states.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection through the processing of untrusted data.
  • Ingestion points: The skill is designed to ingest and act upon user-supplied 'user-data' and 'autoinstall' YAML files (as described in SKILL.md and references/debugging.md).
  • Boundary markers: There are no explicit boundary markers or delimiters configured to prevent the agent from interpreting instructions embedded within the processed configuration data.
  • Capability inventory: The skill utilizes powerful capabilities including file system writes (write_files), package installations, and arbitrary command execution (runcmd) at the system level.
  • Sanitization: While the skill recommends the use of 'cloud-init schema' to validate YAML syntax and structure, it lacks specific mechanisms to sanitize or filter natural language instructions embedded within the data values.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:40 AM