linux-inmemory-stores

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes standard administrative commands such as apt, dnf, systemctl, and redis-cli to manage system services. The script scripts/sk-redis-status.sh uses redis-cli to gather health and security metrics.
  • [PRIVILEGE_ESCALATION]: The skill requires elevated permissions to perform package installations and service restarts via sudo. These actions are within the expected scope of a Linux service management skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from command outputs, which presents a potential surface for indirect prompt injection.
  • Ingestion points: scripts/sk-redis-status.sh reads and parses output from redis-cli INFO and CONFIG GET commands. SKILL.md guides the agent to inspect journalctl logs.
  • Boundary markers: The script uses awk and tr to parse specific key-value pairs from command outputs, providing a degree of structural isolation.
  • Capability inventory: The skill possesses the ability to install packages, modify service configurations, and restart system units.
  • Sanitization: Data is filtered through awk to extract specific fields, reducing the risk of the agent interpreting raw command output as new instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:39 AM