build-and-deploy
Fail
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The
podman buildinstruction in Step 1 contains a hardcoded credential:--build-arg CERT_PASSWORD="localdev321". Hardcoding passwords in scripts or prompts is unsafe practice as it exposes secrets in plain text and can be logged or leaked. - [COMMAND_EXECUTION]: The skill provides a sequence of shell commands for
podmanandawsCLI. These instructions command the agent to perform privileged operations including system pruning, image building, and production service rotation on AWS ECS Fargate.
Recommendations
- AI detected serious security threats
Audit Metadata