deploy
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill automates deployment tasks by executing standard CLI tools such as
npm,bun,aws,docker,gh, andvercel. These commands are run locally to lint, test, build, and deploy the application as specified inSKILL.mdandreferences/workflow.md. - [INDIRECT_PROMPT_INJECTION]: The skill identifies deployment parameters by reading local project configuration files, which is a common pattern for CI/CD tools but introduces a potential surface for indirect instructions.
- Ingestion points: Processes
package.json,next.config.js,nest-cli.json,vite.config.js,vercel.json, and.env.exampleas described inreferences/workflow.md. - Capability inventory: Includes shell execution for building and deploying via
npm,aws,docker, andvercelcommands found across all files. - Boundary markers: The skill does not provide explicit delimiters or instructions to ignore embedded text when reading configuration files.
- Sanitization: No explicit sanitization or validation of the data read from project files is mentioned before it is used to determine command execution.
Audit Metadata