appsmith
Warn
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses a shortened URL (
https://bit.ly/docker-compose-appsmith) to download adocker-compose.ymlfile. Shortened URLs hide the final destination and source, making it difficult for users or automated systems to verify the integrity of the content before it is downloaded. - [COMMAND_EXECUTION]: The instructions direct the agent to run
docker compose up -dusing the file retrieved from the shortened URL. Executing configuration files from opaque external sources without verification represents a security risk. - [EXTERNAL_DOWNLOADS]: The skill fetches configuration and installation resources from the Appsmith official Helm repository (
https://helm.appsmith.com).
Audit Metadata