virtualmin-resellers

Warn

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: All scripts in the package (e.g., scripts/create-reseller.sh, scripts/modify-limits.sh) execute administrative commands using sudo. This provides high-level access to the underlying system's hosting configuration.
  • [CREDENTIALS_UNSAFE]: The scripts create-reseller.sh, create-admin.sh, modify-reseller.sh, and modify-admin.sh accept sensitive passwords as plain-text command-line arguments. Passwords passed this way can be captured in process logs, command history, or by other users on the system.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. Ingestion points: list-admins.sh and list-resellers.sh output account data from the system. Boundary markers: Absent. Capability inventory: All scripts execute sudo virtualmin commands allowing for user, domain, and limit modifications across the host. Sanitization: Absent. Maliciously crafted account names or metadata stored in Virtualmin could potentially influence agent actions when ingested into context.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 6, 2026, 09:54 PM
Security Audit — agent-trust-hub — virtualmin-resellers