oma-tf-infra
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill does not contain any malicious code, obfuscated payloads, or persistence mechanisms. It actively promotes security best practices such as least privilege, OIDC authentication, and secrets management.
- [COMMAND_EXECUTION]: The skill facilitates the execution of cloud-native CLI tools (AWS, GCP, Azure, OCI) and Terraform commands for infrastructure lifecycle management. These operations are essential to the skill's stated purpose and are performed within a standard DevOps context.
- [EXTERNAL_DOWNLOADS]: Workflow examples reference the integration of well-known third-party security and testing tools including Checkov, TFLint, and Open Policy Agent (OPA). These references point to established industry standards for validating infrastructure-as-code and do not involve unverified remote script execution.
Audit Metadata