linux-perf-profiling

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation provides commands to be executed with administrative privileges using sudo for system management and installation.
  • Evidence: Instructions include sudo apt install sysstat, sudo dnf install sysstat, sudo systemctl enable --now sysstat, and sudo install-skills-bin linux-perf-profiling found in SKILL.md and references/profiling-tools.md.
  • [PRIVILEGE_ESCALATION]: The skill directs the user to modify sensitive kernel parameters that govern access to system performance events and kernel memory addresses.
  • Evidence: Instructions include sudo sysctl -w kernel.perf_event_paranoid=1 and references to setting kernel.kptr_restrict=0 to resolve kernel symbols for profiling. These changes lower the kernel's security posture to allow deeper introspection.
  • [EXTERNAL_DOWNLOADS]: The skill references downloading and installing software from external package repositories and source control platforms.
  • Evidence: The skill uses apt and dnf to install packages like sysstat and perf. It also includes instructions to clone a repository from GitHub: git clone https://github.com/brendangregg/FlameGraph.
  • [INDIRECT_PROMPT_INJECTION]: The skill's workflow involves reading and interpreting output from system profiling tools, which constitutes an ingestion of untrusted data into the agent context.
  • Evidence: Ingestion points: Command output from vmstat, iostat, mpstat, and perf (SKILL.md). Boundary markers: Absent. Capability inventory: Ability to install packages, modify kernel settings, and execute system commands. Sanitization: None mentioned.
  • [NO_CODE]: The skill package references external scripts and test files that are not provided within the distributed file bundle.
  • Evidence: References to scripts/sk-perf-snapshot.sh in SKILL.md and tests/test_kaizen_contracts.py in references/agent-runtime-experiments.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 06:07 PM