skills/delorenj/skills/stacks-deploy/Gen Agent Trust Hub

stacks-deploy

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes configuration and deployment files from external source repositories to generate stack entries, which introduces a vulnerability to malicious instructions embedded in those files.
  • Ingestion points: The workflow in SKILL.md (Step 1) directs the agent to read the source repository's compose.yml, Dockerfile, and deployment documentation.
  • Boundary markers: No specific delimiters or boundary instructions are provided to the agent to distinguish between its system instructions and the data being processed from external repositories.
  • Capability inventory: The agent has the capability to execute shell commands (docker, mise), run a custom bash script (op-inject.sh), and write configuration files to the local filesystem (~/docker/stacks/).
  • Sanitization: There is no logic or instruction provided to sanitize, validate, or escape the content extracted from the external source files before it is used to generate deployment artifacts.
  • [COMMAND_EXECUTION]: The skill relies on the execution of various system commands to perform deployment operations.
  • Evidence: SKILL.md and references/deployment-modes.md instruct the agent to use docker build, docker compose pull, and docker compose up as part of the deployment process.
  • Evidence: The skill utilizes mise tasks in the source repository to orchestrate build and deployment workflows.
  • [DYNAMIC_EXECUTION]: The skill provides and executes a custom bash script to manage sensitive environment configuration.
  • Evidence: The op-inject.sh script (found in references/secret-injection.md) is used to resolve 1Password secret references and write them to a local .env file using the op CLI.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — stacks-deploy