linux-server-provisioning
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied configuration data to set up the server environment.\n
- Ingestion points: SKILL.md (Required inputs) and references/provisioning-steps.md (placeholders for hostname and timezone).\n
- Boundary markers: None; inputs are used directly in shell commands.\n
- Capability inventory: Full administrative access via sudo for package management, firewall configuration, and service control.\n
- Sanitization: None; user inputs are expected to be DNS-valid or standard strings for server identification.\n- [EXTERNAL_DOWNLOADS]: Fetches installation scripts and repositories from external sources.\n
- Evidence: Fetches scripts from rclone.org and nodesource.com, and clones the linux-skills repository via git.\n- [REMOTE_CODE_EXECUTION]: Executes scripts directly from external URLs during the provisioning process.\n
- Evidence: Utilizes
curl | bashpatterns for installing rclone and Node.js LTS.\n- [PRIVILEGE_ESCALATION]: Requires administrative access to perform the core functions of the skill.\n - Evidence: Uses
sudofor nearly all provisioning steps, including modifying /etc/ configuration files and installing system services.
Audit Metadata