enabling-cmek-encryption
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides legitimate procedures for managing data-at-rest encryption using official cloud provider CLIs (AWS, GCP, Azure) and the
ccloudtool. All operations are consistent with the documented purpose of enabling CMEK. - [SAFE]: The skill uses placeholders for all sensitive identifiers like ARNs, cluster IDs, and key specifications, ensuring that no actual credentials or secrets are exposed or hardcoded.
- [SAFE]: No malicious patterns such as remote code execution, obfuscation, persistence mechanisms, or unauthorized data exfiltration were identified in the instructions or scripts.
- [SAFE]: The documentation includes extensive safety warnings and prerequisites that help users avoid accidental data loss or misconfiguration, following security best practices for administrative tasks.
Audit Metadata