stacks-deploy
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes configuration and deployment files from external source repositories to generate stack entries, which introduces a vulnerability to malicious instructions embedded in those files.
- Ingestion points: The workflow in
SKILL.md(Step 1) directs the agent to read the source repository'scompose.yml,Dockerfile, and deployment documentation. - Boundary markers: No specific delimiters or boundary instructions are provided to the agent to distinguish between its system instructions and the data being processed from external repositories.
- Capability inventory: The agent has the capability to execute shell commands (
docker,mise), run a custom bash script (op-inject.sh), and write configuration files to the local filesystem (~/docker/stacks/). - Sanitization: There is no logic or instruction provided to sanitize, validate, or escape the content extracted from the external source files before it is used to generate deployment artifacts.
- [COMMAND_EXECUTION]: The skill relies on the execution of various system commands to perform deployment operations.
- Evidence:
SKILL.mdandreferences/deployment-modes.mdinstruct the agent to usedocker build,docker compose pull, anddocker compose upas part of the deployment process. - Evidence: The skill utilizes
misetasks in the source repository to orchestrate build and deployment workflows. - [DYNAMIC_EXECUTION]: The skill provides and executes a custom bash script to manage sensitive environment configuration.
- Evidence: The
op-inject.shscript (found inreferences/secret-injection.md) is used to resolve 1Password secret references and write them to a local.envfile using theopCLI.
Audit Metadata