auditing-cloud-cluster-security
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
ccloudCLI andcockroach sqlto gather configuration data from the cluster. It also employs standard security utilities likeopensslandsslyzeto probe TLS settings. All shell and SQL operations are restricted to read-only commands (e.g.,list,info,SHOW,SELECT). - [EXTERNAL_DOWNLOADS]: The skill references official CockroachDB Cloud API endpoints for networking checks. These interactions are consistent with the vendor's own infrastructure and are used solely for retrieving security metadata.
- [DATA_EXPOSURE]: The skill examines security configurations such as IP allowlists and HBA settings. It includes instructions to avoid logging secrets and focuses on metadata rather than sensitive application data.
Audit Metadata