linux-intrusion-detection

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for managing security services and running rootkit scans using sudo. These are expected administrative tasks for the skill's purpose of intrusion detection.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill processes system logs (e.g., /var/log/auth.log, /var/log/nginx/access.log) and scanner output which contain data from untrusted network sources.
  • Boundary markers: The instructions do not define specific delimiters for log parsing but emphasize correlation with other system signals to verify findings.
  • Capability inventory: System-level administrative access via sudo, package installation using apt or dnf, and IP banning via fail2ban-client.
  • Sanitization: The skill relies on the standard parsing mechanisms of the security tools it manages and encourages manual attribution of detected changes.
  • [PERSISTENCE]: The documentation includes instructions for setting up systemd timers and cron jobs to automate rkhunter and chkrootkit scans. This is a standard security practice for maintaining continuous host monitoring.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:40 AM