coolify
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and process application repository contents, including
docker-compose.ymlandDockerfilefiles, which may originate from untrusted third-party sources. - Ingestion points: The skill utilizes
Read,Glob, andGreptools to process repository structure and file contents. - Boundary markers: The skill mitigates risks by instructing the agent to establish the running platform version (
Rule 0) and prioritize runtime state over static configuration reasoning (Rule 1). - Capability inventory: The skill has access to
Bashfor executing Docker commands andWebFetchfor API interactions. - Sanitization: While no explicit input sanitization is described, the skill provides robust validation logic for reviewing configurations.
- [COMMAND_EXECUTION]: The skill provides numerous patterns for shell command execution to inspect containers (
docker inspect), query internal databases (psql), and manage deployments. These commands are strictly operational and intended for use on the user's own infrastructure. - [EXTERNAL_DOWNLOADS]: The skill references standard package registries (NPM, Composer) and the GitHub Container Registry (GHCR) for fetching application images and dependencies. These references target well-known services and are appropriate for the skill's deployment-focused use case.
Audit Metadata