netlify-deploy

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes multiple shell commands to manage the deployment lifecycle, including npx netlify status, npx netlify login, npx netlify deploy, and package manager commands like npm install.
  • [EXTERNAL_DOWNLOADS]: The skill fetches the official netlify-cli package from the npm registry via npx. Netlify is a well-known technology service, and this behavior is consistent with the skill's stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project metadata from package.json, netlify.toml, and Git remote URLs to configure deployment settings. While these local files represent an external data ingestion surface, this is standard functionality for deployment tooling.
  • Ingestion points: package.json, netlify.toml, and output from git remote show origin.
  • Boundary markers: None specific; the skill relies on CLI parsing of these files.
  • Capability inventory: Subprocess execution of Netlify CLI and package managers.
  • Sanitization: Standard CLI argument handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 01:59 PM
Security Audit — agent-trust-hub — netlify-deploy