deploy
Fail
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill manages and accesses highly sensitive authentication materials, including private SSH keys (e.g.,
~/.ssh/id_ed25519), server login passwords, and sudo passwords for privilege escalation. - [DATA_EXFILTRATION]: Contains instructions to read and display the contents of sensitive configuration files (e.g.,
cat <DEPLOY_PATH>/.env) from the remote server, which exposes potentially secret environment variables directly to the agent's conversation context. - [COMMAND_EXECUTION]: Facilitates arbitrary command execution on remote infrastructure via SSH. This includes performing administrative tasks using
sudo, such as creating system directories and changing file ownership. - [REMOTE_CODE_EXECUTION]: Includes a procedure to download and execute a shell script from Docker's official website (
https://get.docker.com | sh) for automated environment setup. - [EXTERNAL_DOWNLOADS]: Fetches configuration and installation resources from well-known external domains associated with Docker and GitHub.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its processing of external, untrusted data that could contain malicious instructions.
- Ingestion points: Retrieves and processes remote application logs (
docker compose logs) and incoming code/metadata from Git repositories (git pull). - Boundary markers: None identified to separate system instructions from processed external data.
- Capability inventory: Extensive capabilities including remote shell access, privilege escalation (
sudo), and file transfer (scp). - Sanitization: No evidence of sanitization or filtering for data retrieved from logs or external repositories before it is presented to the agent.
Recommendations
- HIGH: Downloads and executes remote code from: https://get.docker.com - DO NOT USE without thorough review
Audit Metadata