linux-mail-server

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions involve executing standard Linux mail administration tools such as postfix, postqueue, postconf, swaks, and dig for configuration, queue management, and network diagnostics. These tools are appropriate for the skill's administrative context.\n- [PRIVILEGE_ESCALATION]: The skill requires administrative privileges via sudo to manage system services (systemctl reload postfix), install diagnostic packages (apt install swaks), and modify configuration files in protected directories like /etc/postfix/ and /etc/dovecot/. This level of access is necessary for server administration.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection by instructing the agent to ingest and analyze untrusted external data, such as mail logs and queue message content, to perform diagnostics.\n
  • Ingestion points: Analyzing /var/log/mail.log, /var/log/maillog, and message contents via postcat -q as described in SKILL.md and references/debugging-delivery.md.\n
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are defined for the agent when processing log or message data.\n
  • Capability inventory: The agent is granted capabilities to write system configuration files, reload services, and perform network operations via swaks and dig.\n
  • Sanitization: The instructions do not specify sanitization or validation logic for the external data processed during troubleshooting.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:40 AM