specsfy-specialist-debian-server

Warn

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute powerful administrative commands, including apt, systemctl, nft, and sysctl, to manage packages, services, network security, and kernel parameters on the host.- [PRIVILEGE_ESCALATION]: The instructions include creating a dedicated deploy user and granting it sudo privileges, as well as managing access to the docker group, which effectively provides root-level access to the server.- [PERSISTENCE]: The skill establishes long-term access by adding SSH public keys to the deploy user's authorized keys and creating or modifying systemd units to ensure services persist across reboots.- [DATA_EXFILTRATION]: The agent is tasked with collecting and recording sensitive server information, including IP addresses, SSH ports, and usernames, in an ansible/inventory.yml file, which constitutes sensitive metadata exposure.- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes data from external sources, such as command outputs and inventory files, to guide its administrative actions.
  • Ingestion points: ansible/inventory.yml and outputs from diagnostic commands like cat /etc/os-release and systemctl --failed.
  • Capability inventory: Execution of apt, systemctl, nft, and sudo commands.
  • Boundary markers: Not utilized.
  • Sanitization: No explicit validation or escaping of system outputs is described.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 3, 2026, 09:50 PM
Security Audit — agent-trust-hub — specsfy-specialist-debian-server