linux-troubleshooting

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to ingest and analyze system logs (e.g., journalctl, Nginx error logs) and process information (top, ps). These data sources can contain untrusted input from external attackers. Since the agent also has capabilities to restart services, kill processes, and execute build tools, there is a risk of indirect prompt injection.
  • Ingestion points: journalctl, tail /var/log/nginx/error.log, ps, top (found in SKILL.md and references/diagnosis-tree.md)
  • Boundary markers: Absent.
  • Capability inventory: systemctl restart, kill, rm, truncate, apt clean, git reset, npm install, composer install (found in SKILL.md and references/diagnosis-tree.md)
  • Sanitization: Absent.
  • [COMMAND_EXECUTION]: The skill relies on high-privilege shell commands using sudo for system monitoring, service management, and recovery actions.
  • [EXTERNAL_DOWNLOADS]: The skill instructions involve installing external packages using apt and dnf, as well as a platform-specific install-skills-bin command.
  • [CREDENTIALS_UNSAFE]: The skill references sensitive file paths such as .env, ~/.mysql-backup.cnf, and ~/.backup-encryption-key during troubleshooting procedures.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 05:18 PM