deployment-consistency

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific configuration files (e.g., Dockerfile, vercel.json) which are external and untrusted. These files could potentially contain malicious instructions that influence the agent's behavior during deployment or auditing.\n- Ingestion points: Configuration file inspection in references/docker.md, references/render.md, and references/vercel.md.\n- Boundary markers: The instructions do not define specific delimiters for separating configuration content from agent instructions.\n- Capability inventory: The skill specifies the ability to 'Apply requested deployment changes' in SKILL.md and verification commands in references/docker.md.\n- Sanitization: No explicit sanitization or validation of the ingested configuration content is mentioned.\n- [COMMAND_EXECUTION]: The skill involves building images and running smoke tests, which implies the execution of shell commands like 'docker build'. This is consistent with the skill's primary purpose of deployment auditing and verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 06:23 PM
Security Audit — agent-trust-hub — deployment-consistency