arthas-doctor
Pass
Audited by Gen Agent Trust Hub on Mar 24, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides documentation on how to use various Arthas shell commands for system diagnosis, such as thread, dashboard, and jvm, to monitor process and system health.
- [DATA_EXFILTRATION]: Documents the use of commands that can access sensitive JVM state, environment variables, and heap memory, including sysenv, sysprop, and heapdump. It explicitly warns users about avoiding the observation of sensitive data like passwords when using the watch command.
- [REMOTE_CODE_EXECUTION]: Explains capabilities for arbitrary code execution within a JVM via OGNL expressions and describes the process of hot-swapping class bytecode using the memory compiler (mc) and redefine commands.
- [NO_CODE]: This skill consists entirely of markdown documentation and knowledge base files. It does not include any executable scripts, binaries, or automated installation procedures, significantly reducing its direct security risk profile.
Audit Metadata