auditing-infrastructure-as-code
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions and reference materials are focused on defensive security auditing of Infrastructure-as-Code (IaC). All identified external resources (Checkov, Trivy, kube-linter, OPA, etc.) are well-known, reputable security tools or official documentation.
- [SAFE]: Hardcoded credential patterns found in the evaluation and example files (e.g., 'sk_live_9f...' and 'hunter2') are explicitly used as test cases for the agent to detect and flag, rather than being used for authentication or exfiltration.
- [SAFE]: The skill maintains a high bar for 'Reviewer discipline', instructing the agent to report only real problems and avoid false positives, which reduces the risk of malicious or misleading output.
Audit Metadata