backend-deploy
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security threats detected.
- [SAFE]: The skill implements security best practices for containerization, including multi-stage builds, pinned image versions, non-root users (
USER node), and exclusion of sensitive files (.env) via.dockerignoretemplates. - [SAFE]: External dependencies and references, such as official Docker images (Node.js, Postgres, Redis) and official GitHub Actions, are sourced from well-known and trusted providers.
- [SAFE]: The skill correctly handles secrets by explicitly instructing to keep credentials out of version-controlled files and recommending the use of environment variables and CI/CD secret management.
Audit Metadata