deploy

Fail

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill manages and accesses highly sensitive authentication materials, including private SSH keys (e.g., ~/.ssh/id_ed25519), server login passwords, and sudo passwords for privilege escalation.
  • [DATA_EXFILTRATION]: Contains instructions to read and display the contents of sensitive configuration files (e.g., cat <DEPLOY_PATH>/.env) from the remote server, which exposes potentially secret environment variables directly to the agent's conversation context.
  • [COMMAND_EXECUTION]: Facilitates arbitrary command execution on remote infrastructure via SSH. This includes performing administrative tasks using sudo, such as creating system directories and changing file ownership.
  • [REMOTE_CODE_EXECUTION]: Includes a procedure to download and execute a shell script from Docker's official website (https://get.docker.com | sh) for automated environment setup.
  • [EXTERNAL_DOWNLOADS]: Fetches configuration and installation resources from well-known external domains associated with Docker and GitHub.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its processing of external, untrusted data that could contain malicious instructions.
  • Ingestion points: Retrieves and processes remote application logs (docker compose logs) and incoming code/metadata from Git repositories (git pull).
  • Boundary markers: None identified to separate system instructions from processed external data.
  • Capability inventory: Extensive capabilities including remote shell access, privilege escalation (sudo), and file transfer (scp).
  • Sanitization: No evidence of sanitization or filtering for data retrieved from logs or external repositories before it is presented to the agent.
Recommendations
  • HIGH: Downloads and executes remote code from: https://get.docker.com - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 16, 2026, 09:09 AM
Security Audit — agent-trust-hub — deploy