deployment

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and downloads configurations and actions from well-known and trusted sources, including the official Docker GitHub organization, the GitHub Actions marketplace (pinned to specific SHAs for security), and Trivy for vulnerability scanning. These are standard tools in the industry and are documented neutrally as required.
  • [COMMAND_EXECUTION]: The skill includes a verify.sh script designed to be run locally or in CI environments to lint Dockerfiles and workflows. It utilizes standard tools like hadolint, actionlint, and trivy. The skill also documents a legitimate deployment trigger via curl to the Coolify API, which is a standard operational requirement for the described workflow.
  • [CREDENTIALS_UNSAFE]: The skill demonstrates high security awareness regarding secrets. It explicitly forbids baking credentials into Docker layers using ARG and instead mandates the use of BuildKit secrets (--mount=type=secret). It also promotes the use of OIDC for cloud authentication to avoid long-lived access keys.
  • [PROMPT_INJECTION]: No evidence of prompt injection attempts, role-play bypasses, or instructions to ignore safety filters was found. The instructions are purely technical and focused on the stated deployment goal.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:36 PM
Security Audit — agent-trust-hub — deployment