project-commands

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes various local repository scripts and binaries, such as './deploy/push-generation.sh', './scripts/register-ssh-public-key.py', and a pinned SOPS binary, to automate infrastructure management.
  • [CREDENTIALS_UNSAFE]: The skill provides instructions to access local sensitive files including SSH private and public keys (e.g., '/.ssh/theau-vps-deploy') and SOPS decryption keys ('/.config/sops/age/keys.txt') necessary for deployment and secret management.
  • [DATA_EXFILTRATION]: The skill performs connectivity checks using 'curl' against various subdomains (e.g., 'theau-vps.duckdns.org', 'authelia.theau.net'). These network operations are intended for verifying service health and align with the infrastructure's domain naming scheme.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 01:18 PM
Security Audit — agent-trust-hub — project-commands