netlify-deploy
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is composed of instructional markdown files for Netlify services and does not contain executable scripts or malicious logic. All external links point to official Netlify domains or verified GitHub repositories.
- [COMMAND_EXECUTION]: The skill facilitates the use of standard Netlify CLI commands, such as 'netlify deploy' and 'netlify init', which are essential for managing site deployments. These operations are within the scope of the skill's intended purpose.
- [CREDENTIALS_UNSAFE]: The documentation references authentication tokens (NETLIFY_AUTH_TOKEN) and environment variables, providing explicit warnings to never commit secrets to Git and to rotate credentials if a leak is detected by the platform's scanner.
- [INDIRECT_PROMPT_INJECTION]: The skill documents processing configuration from netlify.toml and specific parameters from Pull Request descriptions. 1. Ingestion: netlify.toml and PR strings. 2. Boundaries: Delimiters are not explicitly mentioned for PR strings. 3. Capabilities: Netlify CLI execution. 4. Sanitization: The skill provides guidance on secret management and 'fix forward' strategies to mitigate risks from malicious inputs.
Audit Metadata