linux-disaster-recovery

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPERSISTENCECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill makes extensive use of sudo for administrative tasks including package management, service control, filesystem repairs, and bootloader reconfiguration. While necessary for disaster recovery, this grants the agent broad control over the host system.
  • [DATA_EXFILTRATION]: The skill is designed to move data to external cloud storage (specifically Google Drive) using rclone. This involves handling sensitive production data and transferring it over the network.
  • [CREDENTIALS_UNSAFE]: The skill manages and accesses highly sensitive credential files including ~/.backup-encryption-key, ~/.mysql-backup.cnf, and ~/.config/rclone/rclone.conf. The strategy documentation provides instructions for managing these secrets, which are critical for the security of the backup infrastructure.
  • [PERSISTENCE]: The skill provides instructions for establishing persistent automated tasks via cron jobs and systemd timers to maintain regular backup schedules.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes rclone to fetch data from remote sources and suggests using npm and composer for restoring application dependencies, which involves downloading third-party code from public registries.
  • [COMMAND_EXECUTION]: The skill executes powerful system commands such as grub2-mkconfig, update-initramfs, xfs_repair, and e2fsck to repair or reconfigure the operating system.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by instructing the agent to inspect the contents of untrusted backup data (e.g., using head or zcat on SQL dumps) during the validation phase.
  • Ingestion points: File inspection commands in SKILL.md (Step 3) and references/restore-procedures.md (Step 3 and Step 4).
  • Boundary markers: None identified; the agent is instructed to read raw snippets of extracted backup data.
  • Capability inventory: The skill has access to sudo, mysql, psql, rsync, and network tools via rclone.
  • Sanitization: No specific sanitization or filtering of the inspected data is described prior to agent processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 03:13 AM