ext-triage-oci
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates in 'knowledge' mode, providing decision-making logic rather than executable actions. It is designed to be consumed by a parent workflow (plan-marshall) for triaging container findings.
- [SAFE]: The guidelines provided in the standards files (pr-comment-disposition.md, severity.md) strongly advocate for security best practices, including mandatory fixes for critical CVEs, pinning image digests, and preventing root-user execution.
- [SAFE]: No network exfiltration, hardcoded credentials, or obfuscated content were found. The skill's primary function is to define triage outcomes (FIX, REPLY-AND-RESOLVE, ESCALATE) based on established security benchmarks.
- [SAFE]: There are no remote code execution patterns or unverified dependencies. The skill references internal standards (pm-dev-oci:oci-standards) for policy enforcement.
Audit Metadata