linux-sysadmin
Pass
Audited by Gen Agent Trust Hub on Oct 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The hub coordinates the execution of various local administrative tools and scripts, including
python3 scripts/linux_admin_activity.pyfor logging and reporting, andinstall-skills-binfor setting up core utilities. - [PRIVILEGE_ESCALATION]: The skill instructions involve the use of
sudofor high-privilege tasks such as binary installation and service configuration validation. It also requires the agent to operate within protected system paths like/etc/nginxand/usr/local/bin. - [DATA_EXFILTRATION]: The framework includes patterns for syncing data to external storage, specifically mentioning
rcloneintegration for Google Drive backups. - [INDIRECT_PROMPT_INJECTION]: The routing mechanism relies on user-provided descriptions of symptoms and tasks to select specialized workflows.
- Ingestion points: User request fields for server roles and observed symptoms identified in
SKILL.md. - Boundary markers: Absent; no specific markers are used to encapsulate or delimit user-provided content.
- Capability inventory: Broad system access including script execution, privileged command execution via
sudo, and repository management. - Sanitization: Absent; the instructions do not specify validation or escaping of user input during the routing phase.
Audit Metadata