deployment-composer
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows security best practices by requiring explicit user confirmation before performing sensitive actions like production deployments or merging PRs. It limits its own tool usage to a specific set of necessary shell commands (git, gh, ls, find, rg, cat).
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it ingests untrusted data from the repository, such as commit history for changelogs and configuration files (package.json, vercel.json) for deployment routing.
- Ingestion points: Repository configuration files (
package.json,vercel.json,turbo.json) and commit history retrieved via thechangelog-generatordelegation. - Boundary markers: The instructions do not define specific delimiters or "ignore" instructions for the ingested repository content.
- Capability inventory: The skill can execute shell commands via
git,gh,bun,npm, andnpxto build, test, and deploy the application. - Sanitization: No explicit sanitization or validation of the ingested repository content is mentioned in the discovery or routing logic.
- [COMMAND_EXECUTION]: The skill executes repository-defined scripts (e.g.,
npm run build,bun test) and tools (npx biome). This is the intended primary purpose of a deployment orchestration skill and is handled within the scope of local repository access.
Audit Metadata