socai-site-deployment

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill initiates network requests using curl to verify deployment status on the vendor's own domain (socai.io) and official GitHub release endpoints. It also uses pnpm install to fetch project dependencies from the standard registry.
  • [COMMAND_EXECUTION]: The skill executes several CLI tools including vercel, pnpm, and python3. These are used for the primary stated purpose of site deployment, project configuration (via vercel api PATCH requests), and local validation of JSON/XML configuration files.
  • [COMMAND_EXECUTION]: The skill utilizes shell scripting techniques, such as heredocs (<<'EOF') and traps, to programmatically generate temporary configuration files and modify Vercel project settings during the deployment lifecycle.
  • [DATA_EXFILTRATION]: No sensitive data access or exfiltration patterns were identified. Network operations are restricted to verification and standard deployment workflows targeting known vendor and service provider infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 12:15 AM
Security Audit — agent-trust-hub — socai-site-deployment