cpanel-deploy

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a cpanel CLI tool along with local system utilities such as composer, php, and zip. These tools are used for project initialization, dependency management, and archiving during the deployment workflow.
  • [EXTERNAL_DOWNLOADS]: The skill automates the retrieval of software packages from established sources, specifically downloading the WordPress core from wordpress.org and cloning source code from GitHub via the git:clone command.
  • [DATA_EXFILTRATION]: The skill manages sensitive configuration data, including database credentials and environment variables, through the creation and modification of .env, wp-config.php, and config.php files on the target hosting environment. While necessary for deployment, this involves handling sensitive secrets.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes untrusted external data.
  • Ingestion points: The agent reads from local application source directories and clones remote Git repositories (e.g., via git:clone).
  • Boundary markers: The instructions lack explicit markers or delimiters to prevent the agent from interpreting instructions embedded within the source files or environment configurations.
  • Capability inventory: The skill provides significant capabilities, including server-side file writes (file:save, file:upload), database user creation (db:user-create), and execution of local build tools.
  • Sanitization: The skill advises users to wrap database passwords in single quotes to prevent shell interpretation, which provides a basic level of input sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 01:35 AM
Security Audit — agent-trust-hub — cpanel-deploy