Cloud Security Architect
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides secure infrastructure-as-code templates that adhere to industry best practices, including Service Control Policies (SCPs) to deny root usage and require encryption, and Kubernetes Network Policies that implement a default-deny posture.
- [EXTERNAL_DOWNLOADS]: The skill references well-known security tools and official GitHub Actions in its CI/CD pipeline examples, including Checkov, Gitleaks, Trivy, and official AWS credential actions. These are recognized as well-known, trusted services.
- [CREDENTIALS_UNSAFE]: The instructions explicitly emphasize the use of short-lived credentials, OIDC federation, and dedicated secrets managers, while strictly prohibiting hardcoded secrets in code or environment variables.
Audit Metadata