domain-dns-ops

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill orchestrates infrastructure changes by executing local shell scripts (e.g., bin/namecheap-set-ns) and standard CLI tools (cli4, dig, curl, git) within the user's local project directory.
  • [INDIRECT_PROMPT_INJECTION]: Ingestion points: The skill reads configuration from internal files such as DOMAINS.md and DNS.md in the manager repository. Boundary markers: The instructions do not specify delimiters or validation steps for parsing these files. Capability inventory: High; includes the ability to modify DNS zones, update nameservers, and deploy worker routes. Sanitization: Input from these files is used to form command arguments without explicit sanitization mentioned.
  • [CREDENTIALS_UNSAFE]: The skill references a local profile file for loading API credentials for Cloudflare and Namecheap, though it includes a specific rule to minimize token exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:27 PM
Security Audit — agent-trust-hub — domain-dns-ops