auditing-infrastructure-as-code

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and reference materials are focused on defensive security auditing of Infrastructure-as-Code (IaC). All identified external resources (Checkov, Trivy, kube-linter, OPA, etc.) are well-known, reputable security tools or official documentation.
  • [SAFE]: Hardcoded credential patterns found in the evaluation and example files (e.g., 'sk_live_9f...' and 'hunter2') are explicitly used as test cases for the agent to detect and flag, rather than being used for authentication or exfiltration.
  • [SAFE]: The skill maintains a high bar for 'Reviewer discipline', instructing the agent to report only real problems and avoid false positives, which reduces the risk of malicious or misleading output.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 11:23 PM
Security Audit — agent-trust-hub — auditing-infrastructure-as-code