linux-disaster-recovery
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPERSISTENCECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill makes extensive use of
sudofor administrative tasks including package management, service control, filesystem repairs, and bootloader reconfiguration. While necessary for disaster recovery, this grants the agent broad control over the host system. - [DATA_EXFILTRATION]: The skill is designed to move data to external cloud storage (specifically Google Drive) using
rclone. This involves handling sensitive production data and transferring it over the network. - [CREDENTIALS_UNSAFE]: The skill manages and accesses highly sensitive credential files including
~/.backup-encryption-key,~/.mysql-backup.cnf, and~/.config/rclone/rclone.conf. The strategy documentation provides instructions for managing these secrets, which are critical for the security of the backup infrastructure. - [PERSISTENCE]: The skill provides instructions for establishing persistent automated tasks via
cronjobs andsystemdtimers to maintain regular backup schedules. - [EXTERNAL_DOWNLOADS]: The skill utilizes
rcloneto fetch data from remote sources and suggests usingnpmandcomposerfor restoring application dependencies, which involves downloading third-party code from public registries. - [COMMAND_EXECUTION]: The skill executes powerful system commands such as
grub2-mkconfig,update-initramfs,xfs_repair, ande2fsckto repair or reconfigure the operating system. - [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by instructing the agent to inspect the contents of untrusted backup data (e.g., using
headorzcaton SQL dumps) during the validation phase. - Ingestion points: File inspection commands in
SKILL.md(Step 3) andreferences/restore-procedures.md(Step 3 and Step 4). - Boundary markers: None identified; the agent is instructed to read raw snippets of extracted backup data.
- Capability inventory: The skill has access to
sudo,mysql,psql,rsync, and network tools viarclone. - Sanitization: No specific sanitization or filtering of the inspected data is described prior to agent processing.
Audit Metadata