netlify-deploy
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple shell commands to manage the deployment lifecycle, including
npx netlify status,npx netlify login,npx netlify deploy, and package manager commands likenpm install. - [EXTERNAL_DOWNLOADS]: The skill fetches the official
netlify-clipackage from the npm registry vianpx. Netlify is a well-known technology service, and this behavior is consistent with the skill's stated purpose. - [INDIRECT_PROMPT_INJECTION]: The skill processes project metadata from
package.json,netlify.toml, and Git remote URLs to configure deployment settings. While these local files represent an external data ingestion surface, this is standard functionality for deployment tooling. - Ingestion points:
package.json,netlify.toml, and output fromgit remote show origin. - Boundary markers: None specific; the skill relies on CLI parsing of these files.
- Capability inventory: Subprocess execution of Netlify CLI and package managers.
- Sanitization: Standard CLI argument handling.
Audit Metadata