deployment-composer

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes standard development commands such as git, gh, npm, and bun to manage repository workflows. These actions are aligned with the skill's stated purpose and use restrictive tool definitions in the YAML frontmatter.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from repository files (e.g., package.json, workflows) and git metadata. While this creates a potential surface for indirect prompt injection, the risk is mitigated by explicit safety rules requiring human confirmation before high-impact operations. Ingestion points: repo file discovery and metadata reads; Boundary markers: absent; Capability inventory: shell execution of git, gh, npm, and bun; Sanitization: absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 11:16 PM
Security Audit — agent-trust-hub — deployment-composer