cube-deploy
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides an installation command that fetches and executes a shell script from the vendor's official GitHub repository.- [COMMAND_EXECUTION]: The skill interacts with the local system using the
cubeCLI to perform deployment management, resource creation, and credential generation.- [INDIRECT_PROMPT_INJECTION]: The skill processes deployment logs and build status messages which constitute an attack surface for instructions embedded in external data. - Ingestion points: SKILL.md (via
cube logsandcube deployments build-statuscommands) - Boundary markers: Absent
- Capability inventory: SKILL.md (file deployment via
cube deploy, credential generation viacube environments create-token, and variable modification viacube variables set) - Sanitization: Absent
Audit Metadata