deployment-cicd
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides educational templates for CI/CD pipelines and deployment strategies that follow industry standards for security and reliability.
- [SAFE]: Docker configurations in
references/docker-patterns.mddemonstrate secure patterns, including multi-stage builds to minimize image size and attack surface, and the use of non-root users (USER appuser) for running applications. - [SAFE]: GitHub Actions recipes in
references/github-actions-recipes.mdutilize safe secrets management (${{ secrets.DATABASE_URL }}) and provide guidance on least-privilege permissions for theGITHUB_TOKEN. - [SAFE]: Monitoring configurations in
references/monitoring-setup.mdinclude security-conscious logging practices, such as redactingauthorizationandcookieheaders in Pino logs. - [SAFE]: The external tools and actions referenced (e.g., GitHub Actions, Vercel, Docker, Prisma, Sentry) are well-known, established services in the software development ecosystem.
Audit Metadata