linux-mail-server
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions involve executing standard Linux mail administration tools such as
postfix,postqueue,postconf,swaks, anddigfor configuration, queue management, and network diagnostics. These tools are appropriate for the skill's administrative context.\n- [PRIVILEGE_ESCALATION]: The skill requires administrative privileges viasudoto manage system services (systemctl reload postfix), install diagnostic packages (apt install swaks), and modify configuration files in protected directories like/etc/postfix/and/etc/dovecot/. This level of access is necessary for server administration.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection by instructing the agent to ingest and analyze untrusted external data, such as mail logs and queue message content, to perform diagnostics.\n - Ingestion points: Analyzing
/var/log/mail.log,/var/log/maillog, and message contents viapostcat -qas described inSKILL.mdandreferences/debugging-delivery.md.\n - Boundary markers: No specific delimiters or "ignore instructions" warnings are defined for the agent when processing log or message data.\n
- Capability inventory: The agent is granted capabilities to write system configuration files, reload services, and perform network operations via
swaksanddig.\n - Sanitization: The instructions do not specify sanitization or validation logic for the external data processed during troubleshooting.
Audit Metadata