cpanel-deploy
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a
cpanelCLI tool along with local system utilities such ascomposer,php, andzip. These tools are used for project initialization, dependency management, and archiving during the deployment workflow. - [EXTERNAL_DOWNLOADS]: The skill automates the retrieval of software packages from established sources, specifically downloading the WordPress core from
wordpress.organd cloning source code from GitHub via thegit:clonecommand. - [DATA_EXFILTRATION]: The skill manages sensitive configuration data, including database credentials and environment variables, through the creation and modification of
.env,wp-config.php, andconfig.phpfiles on the target hosting environment. While necessary for deployment, this involves handling sensitive secrets. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes untrusted external data.
- Ingestion points: The agent reads from local application source directories and clones remote Git repositories (e.g., via
git:clone). - Boundary markers: The instructions lack explicit markers or delimiters to prevent the agent from interpreting instructions embedded within the source files or environment configurations.
- Capability inventory: The skill provides significant capabilities, including server-side file writes (
file:save,file:upload), database user creation (db:user-create), and execution of local build tools. - Sanitization: The skill advises users to wrap database passwords in single quotes to prevent shell interpretation, which provides a basic level of input sanitization.
Audit Metadata