skills/erphq/skills/deploy-astro/Gen Agent Trust Hub

deploy-astro

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill identifies and accesses a sensitive configuration path at ~/.build-host/credentials.json. This is the standard location for the platform's authentication credentials and is consistent with the skill's deployment purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project source code and git repositories, which are untrusted external data sources. This data is used to inform deployment operations via the build.host API.
  • Ingestion points: Project directory and git repository specified by the user.
  • Boundary markers: None explicitly defined for isolating project content from agent instructions.
  • Capability inventory: Performs network API calls (GET/POST) to build.host for project management and deployment.
  • Sanitization: None specified for the processed project data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 08:55 AM
Security Audit — agent-trust-hub — deploy-astro