appdeploy

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses curl to interact with the AppDeploy API at api-v2.appdeploy.ai for obtaining API keys and executing deployment commands.
  • [EXTERNAL_DOWNLOADS]: Fetches application templates, deployment instructions, and project metadata from the vendor's remote endpoint https://api-v2.appdeploy.ai.
  • [CREDENTIALS_UNSAFE]: The setup process involves storing an API key in a local file named .appdeploy. Although the skill correctly recommends adding this file to .gitignore to prevent accidental commits, it establishes a pattern of storing sensitive credentials in plain text within the project directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 08:21 PM
Security Audit — agent-trust-hub — appdeploy