skills/ericrisco/rsc-harness/fly-io/Gen Agent Trust Hub

fly-io

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides guidelines for using the Fly.io platform and its official CLI tool (flyctl).
  • [DATA_EXFILTRATION]: The skill demonstrates correct secret management using fly secrets set and explicitly warns against hardcoding credentials in configuration files or Dockerfiles. Example keys provided are generic placeholders.
  • [COMMAND_EXECUTION]: The provided scripts/verify.sh script performs structural checks on fly.toml files using grep and the official flyctl validation command if available. This is a standard development utility.
  • [PROMPT_INJECTION]: The skill includes a surface for processing local configuration data via scripts/verify.sh (Category 8).
  • Ingestion points: The fly.toml file specified as an argument to verify.sh (scripts/verify.sh).
  • Boundary markers: Absent.
  • Capability inventory: The script uses grep for pattern matching and executes fly config validate (or flyctl) to check the configuration.
  • Sanitization: None; the script performs read-only structural checks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — fly-io