skills/el-feo/ai-context/kamal/Gen Agent Trust Hub

kamal

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides standard documentation and practical examples for the Kamal 2 deployment tool. All configuration templates and deployment commands are consistent with the tool's intended use for managing infrastructure and containerized web applications.\n- [EXTERNAL_DOWNLOADS]: The skill instructs users to install the Kamal tool via a standard Ruby gem registry ('gem install kamal') and refers to well-known container registries (e.g., 'ghcr.io', 'ECR', 'GCR'). These are legitimate external resources for the documented deployment workflows.\n- [COMMAND_EXECUTION]: The skill details a comprehensive set of commands for remote server and container management, including 'kamal app exec' and 'kamal server exec'. These commands are core to the tool's functionality and are presented in an administrative context for application debugging and maintenance.\n- [INDIRECT_PROMPT_INJECTION]: The skill handles administrative configuration files and deployment hooks, defining a standard ingestion surface.\n
  • Ingestion points: Deployment configuration files ('config/deploy.yml', 'config/deploy.staging.yml') and shell scripts located in the hooks directory ('.kamal/hooks/*').\n
  • Boundary markers: None explicitly defined in the provided instructions for the agent to use when processing these files.\n
  • Capability inventory: Remote execution of shell commands and application processes via the Kamal CLI across all reference files.\n
  • Sanitization: None; the skill assumes the user has administrative control over the deployment environment and its configuration artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 07:24 PM
Security Audit — agent-trust-hub — kamal