skills/ericrisco/rsc-harness/coolify/Gen Agent Trust Hub

coolify

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the user to execute a remote installation script: curl -fsSL https://cdn.coollabs.io/coolify/install.sh | bash. This targets the official domain of the Coolify project (coolify.io / coollabs.io) and is the standard, documented installation method for the service.
  • [COMMAND_EXECUTION]: The skill provides various commands for Docker management and database restoration (e.g., psql, mongorestore, aws s3 cp). These are utility commands necessary for the primary purpose of managing a self-hosted PaaS and do not involve suspicious redirection or exfiltration patterns.
  • [SAFE]: The scripts/verify.sh file is a static linter that checks for common security misconfigurations in Docker Compose files (like hardcoded secrets or exposed ports). It operates locally and does not perform network operations.
  • [SAFE]: The skill explicitly warns against security anti-patterns, such as leaving management ports open to the public or baking secrets into Docker images, demonstrating a security-conscious design.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:36 PM
Security Audit — agent-trust-hub — coolify