linux-mcp-server-administration

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides tools for executing system diagnostics and troubleshooting commands (e.g., systemctl, journalctl, ss, df) on local and remote RHEL-based systems using SSH.
  • [DATA_EXFILTRATION]: The skill accesses and retrieves highly sensitive system information, specifically targeting authentication logs (/var/log/secure) and security audit logs (/var/log/audit/audit.log), which may contain credentials, session tokens, or other sensitive security data.
  • [EXTERNAL_DOWNLOADS]: The installation instructions require downloading the linux-mcp-server package from PyPI and cloning source code from an external GitHub repository (rhel-lightspeed/linux-mcp-server) that is not categorized as a trusted source.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from system logs and process outputs, creating a vulnerability where malicious strings in those logs could be interpreted as instructions by the AI agent. Ingestion points: System log files (e.g., /var/log/messages), journal entries, and system process metadata. Boundary markers: The skill lacks explicit markers to distinguish between legitimate log data and potentially malicious instructions embedded within the logs. Capability inventory: Includes remote command execution via SSH, file reading, and network connectivity testing. Sanitization: There is no mention of sanitization or filtering of external content before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 10:43 PM
Security Audit — agent-trust-hub — linux-mcp-server-administration