gitops-repo-audit
Pass
Audited by Gen Agent Trust Hub on May 28, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes bundled scripts (
discover.sh,validate.sh,check-deprecated.sh) to perform its primary function. These scripts execute standard CLI utilities includingawk,yq,git,kustomize,kubeconform, and thefluxCLI. These operations are restricted to the local directory provided by the user for auditing purposes. - [SAFE]: All external URL references within the skill's instructions and reference documentation point to official Flux CD or Flux Operator project sites (
fluxcd.io,fluxoperator.dev) and their corresponding GitHub repositories. These are verified vendor resources and are considered safe. - [SAFE]: The skill implements proactive security checks, such as scanning for unencrypted secrets and hardcoded credentials within the user's repository, which enhances the security posture of the target environment.
Audit Metadata