linux-sysctl-tuning

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes sudo to execute commands such as sysctl --system and modprobe tcp_bbr to manage kernel parameters and load necessary kernel modules.
  • [PERSISTENCE]: Instructions include creating and modifying configuration files within /etc/sysctl.d/, ensuring that performance tunings remain effective after system reboots.
  • [PRIVILEGE_ESCALATION]: The skill requires administrative (sudo) access to perform its primary functions, including writing to protected system directories and modifying live kernel state.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon performance profiling evidence and host inspection data from external sources, which presents an attack surface for indirect injection.
  • Ingestion points: The skill reads measured bottleneck data and performance profiling evidence (SKILL.md).
  • Boundary markers: No specific delimiters or safety warnings are provided to prevent the agent from interpreting instructions embedded within the performance data.
  • Capability inventory: The skill possesses file-write capabilities (via tee to /etc/sysctl.d/), kernel module loading (modprobe), and system-wide configuration application (sysctl --system).
  • Sanitization: There is no evidence of validation or sanitization of the input data before it is used to generate system configuration changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:39 AM