linux-intrusion-detection
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for managing security services and running rootkit scans using
sudo. These are expected administrative tasks for the skill's purpose of intrusion detection. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill processes system logs (e.g.,
/var/log/auth.log,/var/log/nginx/access.log) and scanner output which contain data from untrusted network sources. - Boundary markers: The instructions do not define specific delimiters for log parsing but emphasize correlation with other system signals to verify findings.
- Capability inventory: System-level administrative access via
sudo, package installation usingaptordnf, and IP banning viafail2ban-client. - Sanitization: The skill relies on the standard parsing mechanisms of the security tools it manages and encourages manual attribution of detected changes.
- [PERSISTENCE]: The documentation includes instructions for setting up systemd timers and cron jobs to automate
rkhunterandchkrootkitscans. This is a standard security practice for maintaining continuous host monitoring.
Audit Metadata