user-management

Warn

Audited by Gen Agent Trust Hub on Mar 27, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for elevating user privileges on the host system. Evidence: usermod -aG sudo username.\n- [COMMAND_EXECUTION]: The documentation includes high-risk configurations for the sudoers file that enable passwordless root access for all commands. Evidence: username ALL=(ALL) NOPASSWD: ALL.\n- [COMMAND_EXECUTION]: The skill provides examples for granting passwordless access to the Docker binary, which is a known vector for gaining full root privileges on the host system. Evidence: %developers ALL=(ALL) NOPASSWD: /usr/bin/docker.\n- [PROMPT_INJECTION]: The skill contains deceptive metadata where the stated author does not match the registered skill provider, which can mislead users regarding the origin and safety of the content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 27, 2026, 02:05 PM