project-commands
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes various local repository scripts and binaries, such as './deploy/push-generation.sh', './scripts/register-ssh-public-key.py', and a pinned SOPS binary, to automate infrastructure management.
- [CREDENTIALS_UNSAFE]: The skill provides instructions to access local sensitive files including SSH private and public keys (e.g., '
/.ssh/theau-vps-deploy') and SOPS decryption keys ('/.config/sops/age/keys.txt') necessary for deployment and secret management. - [DATA_EXFILTRATION]: The skill performs connectivity checks using 'curl' against various subdomains (e.g., 'theau-vps.duckdns.org', 'authelia.theau.net'). These network operations are intended for verifying service health and align with the infrastructure's domain naming scheme.
Audit Metadata