devops-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill enforces strong security postures by instructing the agent to never store secrets in code or environment files, instead mandating the use of dedicated secret managers (e.g., AWS Secrets Manager, Vault).
  • [SAFE]: Instructions include mandatory validation steps, such as performing terraform plan and linting configurations, which serve as human-in-the-loop checkpoints to prevent destructive or unintended changes.
  • [SAFE]: All scripts and code snippets in the reference documentation are standard engineering templates for well-known tools like Kubernetes, Docker, and Terraform, intended for user adaptation rather than autonomous malicious execution.
  • [SAFE]: The skill incorporates security-focused automation examples, such as integrating Trivy for image scanning and Cosign for artifact signing, promoting supply chain security.
  • [SAFE]: No obfuscated URLs, Base64-encoded payloads, or hidden instructions were found in the skill's metadata or instructional content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 05:05 AM
Security Audit — agent-trust-hub — devops-engineer