app-platform-router
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill suite utilizes doctl, gh, and psql CLIs to manage infrastructure. Commands are constructed using parameters or environment variables, following secure patterns.
- [CREDENTIALS_UNSAFE]: The repository enforces a strict credential hierarchy, prioritizing GitHub Secrets and App Platform bindable variables. No hardcoded secrets were found in operational scripts; credentials in test files are mocks.
- [DATA_EXFILTRATION]: Network operations are restricted to well-known domains including DigitalOcean and GitHub. Scripts are designed to transmit secrets directly to GitHub Secrets using the gh CLI, ensuring the agent does not handle plaintext values.
- [PROMPT_INJECTION]: The migration skill ingests data from external Git repositories for analysis. This attack surface is mitigated by using specialized analysis scripts rather than direct instruction execution.
- [EXTERNAL_DOWNLOADS]: The suite fetches configuration and templates from GitHub and uses diagnostic images from GHCR. These downloads are associated with the vendor's provided templates and infrastructure maintenance tools.
Audit Metadata