auditing-cloud-cluster-security

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the ccloud CLI and cockroach sql to gather configuration data from the cluster. It also employs standard security utilities like openssl and sslyze to probe TLS settings. All shell and SQL operations are restricted to read-only commands (e.g., list, info, SHOW, SELECT).
  • [EXTERNAL_DOWNLOADS]: The skill references official CockroachDB Cloud API endpoints for networking checks. These interactions are consistent with the vendor's own infrastructure and are used solely for retrieving security metadata.
  • [DATA_EXPOSURE]: The skill examines security configurations such as IP allowlists and HBA settings. It includes instructions to avoid logging secrets and focuses on metadata rather than sensitive application data.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 09:41 PM
Security Audit — agent-trust-hub — auditing-cloud-cluster-security