golive
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill frequently executes local shell commands using Node.js to perform deployment tasks, environment wiring, and verification. It interacts with several vendor-provided CLI tools, including Vercel, Supabase, Resend, GoDaddy (gddy), Stripe, and Neon.
- [REMOTE_CODE_EXECUTION]: A self-update mechanism is implemented in
scripts/install-lib.mjsandscripts/install-cli.mjs. It allows the skill to download a new release bundle from the author's GitHub repository and execute it. While this is an off-by-default feature requiring human opt-in, the process involves downloading external scripts and executing them viaspawnSyncfor a 'smoke test' verification. - [EXTERNAL_DOWNLOADS]: The skill facilitates downloading updates from
github.com/mikehasa/golive-skill. It also provides instructions for users to download and install various third-party CLI tools and dependencies from well-known services like Vercel, Resend, and GoDaddy. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a significant attack surface for indirect prompt injection as it ingests and processes untrusted data from the user's repository (source files, configuration, lockfiles) and from external provider API responses.
- Ingestion points: The
detectcommand scans the entire application codebase and configuration files. Theverifyandstatuscommands process live API responses and fetch production assets. - Boundary markers: The skill instructions (SKILL.md Rule 7) explicitly direct the agent to treat all external content as data and to report any command-like instructions to the human instead of acting on them.
- Capability inventory: The skill has broad capabilities including local file writes to the
.golive/directory anddocs/, network operations viafetchand vendor CLIs, and shell command execution. - Sanitization: The agent is instructed to visually confirm operations with the human and uses specific check IDs to narrow the scope of validation.
- [DYNAMIC_EXECUTION]: The
defaultSmokefunction inscripts/install-lib.mjsdynamically generates a 'guard' script at runtime. This script is used as a pre-load requirement (--require) when executing a new release during the smoke test to intercept and block network or subprocess calls, acting as a temporary sandbox.
Audit Metadata