skills/shipshitdev/skills/deploy/Gen Agent Trust Hub

deploy

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill automates deployment tasks by executing standard CLI tools such as npm, bun, aws, docker, gh, and vercel. These commands are run locally to lint, test, build, and deploy the application as specified in SKILL.md and references/workflow.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies deployment parameters by reading local project configuration files, which is a common pattern for CI/CD tools but introduces a potential surface for indirect instructions.
  • Ingestion points: Processes package.json, next.config.js, nest-cli.json, vite.config.js, vercel.json, and .env.example as described in references/workflow.md.
  • Capability inventory: Includes shell execution for building and deploying via npm, aws, docker, and vercel commands found across all files.
  • Boundary markers: The skill does not provide explicit delimiters or instructions to ignore embedded text when reading configuration files.
  • Sanitization: No explicit sanitization or validation of the data read from project files is mentioned before it is used to determine command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:10 AM
Security Audit — agent-trust-hub — deploy