managing-certificates-and-encryption
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and commands for managing certificates and encryption keys, which is its primary stated purpose.\n- [COMMAND_EXECUTION]: Uses standard CLI tools (cockroach, aws, gcloud, az, kubectl, openssl) for infrastructure management. These operations are expected for the skill's functionality and do not involve suspicious execution patterns.\n- [CREDENTIALS_UNSAFE]: No hardcoded credentials were found. The skill correctly instructs the use of environment variables (e.g., $COCKROACH_API_KEY) and secure file permissions (e.g., chmod 0600 for keys), following industry best practices for secret management.\n- [EXTERNAL_DOWNLOADS]: Accesses official CockroachDB Cloud APIs (cockroachlabs.cloud) for CMEK management. These network operations are directed at the vendor's own infrastructure and do not represent a security risk.
Audit Metadata