deployment-composer

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices by requiring explicit user confirmation before performing sensitive actions like production deployments or merging PRs. It limits its own tool usage to a specific set of necessary shell commands (git, gh, ls, find, rg, cat).
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it ingests untrusted data from the repository, such as commit history for changelogs and configuration files (package.json, vercel.json) for deployment routing.
  • Ingestion points: Repository configuration files (package.json, vercel.json, turbo.json) and commit history retrieved via the changelog-generator delegation.
  • Boundary markers: The instructions do not define specific delimiters or "ignore" instructions for the ingested repository content.
  • Capability inventory: The skill can execute shell commands via git, gh, bun, npm, and npx to build, test, and deploy the application.
  • Sanitization: No explicit sanitization or validation of the ingested repository content is mentioned in the discovery or routing logic.
  • [COMMAND_EXECUTION]: The skill executes repository-defined scripts (e.g., npm run build, bun test) and tools (npx biome). This is the intended primary purpose of a deployment orchestration skill and is handled within the scope of local repository access.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:05 PM
Security Audit — agent-trust-hub — deployment-composer