linux-log-management

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze log files, such as Nginx and Apache access logs, which contain data generated by external network actors (e.g., User-Agent strings, request paths). This data is inherently untrusted and could be used to deliver adversarial prompts intended to influence the agent's behavior during log analysis.
  • Ingestion points: The skill reads from /var/log/nginx/access.log, /var/log/auth.log, and journalctl output.
  • Boundary markers: The skill recommends using time-bounded slices and mentions redacting sensitive fields, which provides some isolation but is not a complete barrier against malicious input.
  • Capability inventory: The agent has access to sensitive files via sudo tail and sudo grep, and can execute administrative commands like sudo systemctl restart and sudo logrotate.
  • Sanitization: The instructions include a requirement to redact secrets and personal data from collected evidence before export.
  • [REMOTE_CODE_EXECUTION]: The SKILL.md file encourages the installation of several custom shell scripts (e.g., sk-journal-errors.sh, sk-access-log-report.sh) using a platform-specific utility install-skills-bin. Because the scripts/ directory containing these files was not provided in the analyzed bundle, the code within these scripts could not be audited for security.
  • [PRIVILEGE_ESCALATION]: The skill relies extensively on the sudo command for nearly all log inspection and management tasks. While these privileges are necessary for standard Linux log administration, the documentation instructs the agent to operate in a high-privilege mode by default.
  • [COMMAND_EXECUTION]: The skill provides a large collection of complex command-line recipes using awk, sed, grep, and journalctl. These commands are used to process system logs, detect attack patterns, and manage service states (e.g., restarting systemd-journald).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 03:13 AM