skills/hussainweb/skills/coolify/Gen Agent Trust Hub

coolify

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and process application repository contents, including docker-compose.yml and Dockerfile files, which may originate from untrusted third-party sources.
  • Ingestion points: The skill utilizes Read, Glob, and Grep tools to process repository structure and file contents.
  • Boundary markers: The skill mitigates risks by instructing the agent to establish the running platform version (Rule 0) and prioritize runtime state over static configuration reasoning (Rule 1).
  • Capability inventory: The skill has access to Bash for executing Docker commands and WebFetch for API interactions.
  • Sanitization: While no explicit input sanitization is described, the skill provides robust validation logic for reviewing configurations.
  • [COMMAND_EXECUTION]: The skill provides numerous patterns for shell command execution to inspect containers (docker inspect), query internal databases (psql), and manage deployments. These commands are strictly operational and intended for use on the user's own infrastructure.
  • [EXTERNAL_DOWNLOADS]: The skill references standard package registries (NPM, Composer) and the GitHub Container Registry (GHCR) for fetching application images and dependencies. These references target well-known services and are appropriate for the skill's deployment-focused use case.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 03:19 AM
Security Audit — agent-trust-hub — coolify