ec2-backend-deployer
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions to fetch official installation scripts from well-known services, specifically Docker (via get.docker.com) and Tailscale (via tailscale.com), to configure the EC2 environment.
- [REMOTE_CODE_EXECUTION]: Deployment setup scripts for the EC2 instance involve piping remote content directly into the shell (curl | sh). These actions target official domains and are consistent with standard infrastructure-as-code and setup procedures.
- [COMMAND_EXECUTION]: The guide provides various shell commands for project discovery (reading package.json, checking directory structures) and system administration (managing Docker groups, installing packages, setting file permissions).
- [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface for untrusted data, as it reads local project files like package.json and GitHub workflow configurations to automate deployment settings. This creates a potential surface for indirect injection from repository content, though the impact is limited to the configuration generation process.
- [PERSISTENCE]: The skill provides templates for creating automated maintenance tasks, including a daily cron job for Docker system pruning and image cleanup to maintain server disk space.
Audit Metadata