deploy-dispatch
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and inspect untrusted external data including pull request bodies, commit messages, and repository file contents to establish deployment context. While the instructions explicitly warn the agent to treat this content as data only and to disregard any embedded instructions, this ingestion pattern constitutes a potential indirect prompt injection surface.
- [SAFE]: The skill configuration includes the
disable-model-invocation: trueflag, which serves as a security control requiring a direct and explicit user command (e.g.,/deploy) to activate the skill. This prevents the agent from autonomously triggering deployment workflows. - [SAFE]: All referenced delegation targets (deploy, deployment-composer, ec2-backend-deployer, monitoring-setup, devcontainer-setup) are treated as internal skill components, and the skill includes specific anti-patterns to prevent unauthorized auto-chaining of commands or guessing of arguments.
Audit Metadata