coolify-operator

Fail

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install the Coolify CLI by downloading and executing scripts directly from the official coollabsio GitHub repository. These scripts are piped to shell interpreters (bash and PowerShell) for installation.
  • Evidence: curl -fsSL https://raw.githubusercontent.com/coollabsio/coolify-cli/main/scripts/install.sh | bash in SKILL.md.
  • Evidence: irm https://raw.githubusercontent.com/coollabsio/coolify-cli/main/scripts/install.ps1 | iex in SKILL.md.
  • [DATA_EXPOSURE]: Documentation includes examples of commands that access sensitive local files, such as SSH private keys and local configuration files containing API tokens.
  • Evidence: Example coolify private-key add mykey ~/.ssh/id_rsa in SKILL.md.
  • Evidence: Reference to sensitive configuration storage at ~/.config/coolify/config.json.
  • [COMMAND_EXECUTION]: The skill utilizes the coolify CLI tool to perform management operations, including application lifecycle control, environment variable synchronization, and server provisioning.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection by processing external data such as application logs and Git repository contents while having extensive command execution capabilities.
  • Ingestion points: The skill ingests untrusted data when retrieving logs via coolify app logs or coolify app deployments logs and when interacting with external Git repositories.
  • Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from following commands embedded within the retrieved logs.
  • Capability inventory: The skill can execute critical deployment commands, modify environment variables, and provision cloud servers.
  • Sanitization: No specific sanitization or filtering logic is implemented for the processed log outputs.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/coollabsio/coolify-cli/main/scripts/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 23, 2026, 04:17 PM
Security Audit — agent-trust-hub — coolify-operator