cube-deploy

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides an installation command that fetches and executes a shell script from the vendor's official GitHub repository.- [COMMAND_EXECUTION]: The skill interacts with the local system using the cube CLI to perform deployment management, resource creation, and credential generation.- [INDIRECT_PROMPT_INJECTION]: The skill processes deployment logs and build status messages which constitute an attack surface for instructions embedded in external data.
  • Ingestion points: SKILL.md (via cube logs and cube deployments build-status commands)
  • Boundary markers: Absent
  • Capability inventory: SKILL.md (file deployment via cube deploy, credential generation via cube environments create-token, and variable modification via cube variables set)
  • Sanitization: Absent
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 04:55 AM
Security Audit — agent-trust-hub — cube-deploy