python-dtrace-profiling

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill requires the use of sudo to run DTrace, granting root-level permissions to the instrumentation process.
  • [COMMAND_EXECUTION]: The guide includes instructions for running various shell commands to set up the environment and execute the profiler.
  • [EXTERNAL_DOWNLOADS]: The setup instructions include pyenv install and pip install, which download Python interpreters and packages from remote registries. These are well-known services and do not escalate the verdict on their own.
  • [INDIRECT_PROMPT_INJECTION]: The skill traces programs that fetch external web content via requests and beautifulsoup4, creating a risk that malicious data captured in the trace logs could influence the agent during analysis.
  • Ingestion points: DTrace output logs and .trace files generated during execution.
  • Boundary markers: No delimiters or isolation instructions are provided for separating trace data from agent instructions.
  • Capability inventory: Shell access via sudo and file redirection for log creation.
  • Sanitization: No sanitization of the trace output is described before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 02:00 AM
Security Audit — agent-trust-hub — python-dtrace-profiling