land-and-deploy

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from PR bodies and external website content. Evidence chain: 1) Ingestion points: gh pr view (PR body) and aside repl (web content). 2) Boundary markers: Untrusted web content is wrapped in markers. 3) Capability inventory: Full shell, file write, and network access. 4) Sanitization: Uses gstack-issue-guard for PR bodies.
  • [DYNAMIC_EXECUTION]: The skill executes dynamically generated code in two ways: 1) Using eval on the output of local binaries (gstack-slug, gstack-diff-scope) to set environment variables. 2) Generating and executing JavaScript for browser automation via aside repl.
  • [COMMAND_EXECUTION]: Automates the land-and-deploy workflow by executing multiple shell commands for git operations, GitHub CLI interactions, and platform-specific deployments (e.g., Fly.io, Heroku).
  • [EXTERNAL_DOWNLOADS]: Mentions aside.com as a source for the Aside browser, recommending its use for macOS-based web actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 07:11 AM
Security Audit — agent-trust-hub — land-and-deploy