deployment-cicd

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides educational templates for CI/CD pipelines and deployment strategies that follow industry standards for security and reliability.
  • [SAFE]: Docker configurations in references/docker-patterns.md demonstrate secure patterns, including multi-stage builds to minimize image size and attack surface, and the use of non-root users (USER appuser) for running applications.
  • [SAFE]: GitHub Actions recipes in references/github-actions-recipes.md utilize safe secrets management (${{ secrets.DATABASE_URL }}) and provide guidance on least-privilege permissions for the GITHUB_TOKEN.
  • [SAFE]: Monitoring configurations in references/monitoring-setup.md include security-conscious logging practices, such as redacting authorization and cookie headers in Pino logs.
  • [SAFE]: The external tools and actions referenced (e.g., GitHub Actions, Vercel, Docker, Prisma, Sentry) are well-known, established services in the software development ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — deployment-cicd