strut
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of the
strutCLI to perform stack management tasks. These include deployment (strut release), backup operations (strut backup all), and container management (strut stop,strut rebuild). These commands are standard for a DevOps management tool. - Evidence: SKILL.md and multiple reference files detail commands like
strut <stack> release --env prodandstrut <stack> backup all --env prod. - [DATA_EXPOSURE]: The skill manages
.envfiles containing sensitive credentials. It follows security best practices by setting file permissions to0600and advising against hardcoding secrets indocker-compose.yml. - Evidence: SKILL.md states 'Files are written mode 0600' and 'shell expansion ($VAR, $(cmd)) is not evaluated' for env files.
- [PRIVILEGE_ESCALATION]: Mention of
VPS_SUDO=trueis used for managing Docker containers that require root privileges on the target VPS. This is an expected requirement for Docker management utilities. - Evidence: references/backups.md notes 'Databases running inside Docker containers may require VPS_SUDO=true'.
- [REMOTE_CODE_EXECUTION]: The skill facilitates execution of commands on remote VPS hosts via SSH. This is the core intended functionality for a VPS management skill.
- Evidence: references/debugging.md and references/deployment.md describe
execandshellcommands targeting the remote host.
Audit Metadata