skills/nodeops-app/skills/createos/Gen Agent Trust Hub

createos

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill facilitates the deployment of code to the CreateOS cloud platform. Network operations are restricted to official vendor domains associated with nodeops.network and nodeops-app subdomains.
  • [DATA_EXPOSURE]: The skill includes functionality to read local files and directories for the purpose of uploading them to the platform. This behavior is documented and central to the skill's purpose as a deployment utility. It implements standard ignore patterns to skip sensitive local directories such as .git and node_modules.
  • [CREDENTIALS_SAFE]: Authentication is handled via API keys passed in headers or automatically via the MCP server environment. Documentation explicitly advises against hardcoding secrets and provides instructions for using environment variables for sensitive data.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as local project files and GitHub repository metadata. While this creates a potential attack surface if processed files contain malicious instructions, this risk is inherent to the tool's primary purpose of code deployment and transport.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:18 AM
Security Audit — agent-trust-hub — createos