host

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches deployment templates and configuration metadata from GitHub repositories under the 'kasperhonore' account. These are identified as vendor-owned resources used for legitimate configuration purposes.
  • [COMMAND_EXECUTION]: Utilizes Coolify MCP tools to execute container-level commands for health verification and diagnostic checks. This is a documented and essential function for the skill's infrastructure deployment tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill researches third-party project documentation, which constitutes an indirect prompt injection surface. To mitigate this, it employs a subagent to summarize external content into a deployability report rather than processing untrusted data directly in the main execution context.
  • [DYNAMIC_EXECUTION]: Generates Docker Compose manifests and application environment configurations at runtime based on the findings from its research phase. This dynamic generation is the intended primary function of the skill and is performed within the constraints of the platform's deployment API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 05:01 PM
Security Audit — agent-trust-hub — host