linux-disk-storage
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous instructions for executing high-risk system commands using
sudo, includingfdisk,mkfs,truncate,wipefs, andbadblocks -w. These tools are necessary for disk management but can lead to irreversible data loss if applied to the wrong device. - [PRIVILEGE_ESCALATION]: Nearly all operations described in the skill require
sudoprivileges, including creating swapfiles, modifying/etc/fstab, and managing network mounts. While consistent with the skill's purpose, it relies on the agent having extensive administrative control over the host. - [EXTERNAL_DOWNLOADS]: The skill automates the installation of system utilities such as
cifs-utils,smbclient,nfs-common, andautofsusing standard package managers (aptanddnf) from official repositories. - [PERSISTENCE]: The skill manages system persistence by modifying
/etc/fstabto ensure network shares and swapfiles are mounted at boot. It also provides instructions for configuringautofsand systemd mount units. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection via the processing of untrusted filesystem metadata.
- Ingestion points: Metadata and filenames ingested through commands like
df,du,lsblk,findmnt, andfind(documented inSKILL.mdandreferences/storage-reference.md). - Boundary markers: Absent; the skill processes standard shell command output without specific delimiters or warnings for the agent regarding embedded content.
- Capability inventory: The skill possesses extensive capabilities for file system mutation, including
rm,truncate,mkfs, andmount(inSKILL.mdandscripts/sk-cifs-mount.sh). - Sanitization: Absent; the provided scripts and instructions do not include specific sanitization logic for metadata retrieved from the filesystem before it is processed by the agent.
Audit Metadata