stash-deployment

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides detailed procedural guidance for performing database encryption rollouts using the CipherStash EQL v3 system. The instructions promote security best practices, such as multi-stage deployment ladders to prevent data loss and human-gated decision points.
  • [CREDENTIALS_UNSAFE]: The documentation references environment variables used for authentication (CS_WORKSPACE_CRN, CS_CLIENT_ID, CS_CLIENT_KEY, CS_CLIENT_ACCESS_KEY). The skill provides instructions on how to generate and securely store these credentials in an environment's secret store and explicitly cautions against printing or logging these secrets.
  • [COMMAND_EXECUTION]: The skill includes shell command examples for CipherStash and Prisma CLI tools (stash encrypt backfill, prisma-next db init). These commands are standard for managing the vendor's encryption lifecycle and database migrations.
  • [EXTERNAL_DOWNLOADS]: The skill mentions various Node.js packages provided by the author (CipherStash) and Prisma. These are standard dependencies for the integration described and are used within their intended functional scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 03:34 PM
Security Audit — agent-trust-hub — stash-deployment