app-platform-router

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill suite utilizes doctl, gh, and psql CLIs to manage infrastructure. Commands are constructed using parameters or environment variables, following secure patterns.
  • [CREDENTIALS_UNSAFE]: The repository enforces a strict credential hierarchy, prioritizing GitHub Secrets and App Platform bindable variables. No hardcoded secrets were found in operational scripts; credentials in test files are mocks.
  • [DATA_EXFILTRATION]: Network operations are restricted to well-known domains including DigitalOcean and GitHub. Scripts are designed to transmit secrets directly to GitHub Secrets using the gh CLI, ensuring the agent does not handle plaintext values.
  • [PROMPT_INJECTION]: The migration skill ingests data from external Git repositories for analysis. This attack surface is mitigated by using specialized analysis scripts rather than direct instruction execution.
  • [EXTERNAL_DOWNLOADS]: The suite fetches configuration and templates from GitHub and uses diagnostic images from GHCR. These downloads are associated with the vendor's provided templates and infrastructure maintenance tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:32 AM
Security Audit — agent-trust-hub — app-platform-router