skills/gfargo/skills/strut/Gen Agent Trust Hub

strut

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of the strut CLI to perform stack management tasks. These include deployment (strut release), backup operations (strut backup all), and container management (strut stop, strut rebuild). These commands are standard for a DevOps management tool.
  • Evidence: SKILL.md and multiple reference files detail commands like strut <stack> release --env prod and strut <stack> backup all --env prod.
  • [DATA_EXPOSURE]: The skill manages .env files containing sensitive credentials. It follows security best practices by setting file permissions to 0600 and advising against hardcoding secrets in docker-compose.yml.
  • Evidence: SKILL.md states 'Files are written mode 0600' and 'shell expansion ($VAR, $(cmd)) is not evaluated' for env files.
  • [PRIVILEGE_ESCALATION]: Mention of VPS_SUDO=true is used for managing Docker containers that require root privileges on the target VPS. This is an expected requirement for Docker management utilities.
  • Evidence: references/backups.md notes 'Databases running inside Docker containers may require VPS_SUDO=true'.
  • [REMOTE_CODE_EXECUTION]: The skill facilitates execution of commands on remote VPS hosts via SSH. This is the core intended functionality for a VPS management skill.
  • Evidence: references/debugging.md and references/deployment.md describe exec and shell commands targeting the remote host.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 04:40 PM
Security Audit — agent-trust-hub — strut