Skip to main content

ocas-custodian

Automates monitoring and maintenance of agent platforms, fixing operational failures and optimizing system health during quiet hours.

Install this skill

or
55/100

Security score

The ocas-custodian skill was audited on Oct 4, 2026 and we found 3 security issues across 1 threat category, including 3 high-severity. Review the findings below before installing.

Categories Tested

Security Issues

high line 153

Windows registry startup

SourceSKILL.md
151| Tool name | Args | Does |
152|---|---|---|
153| `custodian_scan` | `mode: light \| deep` | light = tail gateway log, cron registry, retry failed fixes; deep = full sweep (`references/deep-scan.md`). **⚠️ Verified broken 2026-10-04:** with `mode: deep` it returned `"mode": "light"`, charged ONE traceback to FOUR distinct `fingerprint_id`s with byte-identical evidence, included entries dated two days before the run, and wrote its journal to `/root/.hermes/commons/...` instead of the profile commons root. **Do not use its counts as a census** — treat output as unverified until `returned_mode == requested_mode` and no two entries share identical evidence across distinct fingerprint ids. Run `scripts/custodian_sweep.py` (self-test first) plus direct registry probes instead. Issue: `oc_custodian_scan_tool_returns_light_and_misattributes_identical_evidence_20261004T0301Z`. |
154| `custodian_issues` | `action: list \| summary \| resolve` (+`issue_id`) | issue triage |
155| `custodian_cron_health` | none | cron health report + alert gate |
high line 196

Windows registry startup

SourceSKILL.md
194
195**Post-fix verification:** after any Tier 1 fix, re-check the targeted log/config, then
196close the registry loop with `hermes cron run <id>` (batch:
197`scripts/verify_fixes_cron_run.py`).
198
high line 291

Windows registry startup

SourceSKILL.md
289| `write_file` "missing required field: path" | fallback `cat > /path << 'EOF' ... EOF` |
290| jobs.json parses to 0 jobs | `d.get("jobs", [])`; re-inspect raw head before concluding 0 |
291| `last_status=error` after a fix | registry lags — `hermes cron run <id>` flips it; stale ≠ failure |
292| literal `gateway restart` in command | interlock blocks — reword (e.g. "gateway reload") |
293| `append_issue_row.py` exits 2 | the row was appended and its open-count delta disagreed — inspect the row before trusting the store |
Scanned on Oct 4, 2026
View Security Dashboard
Installation guide →