skills/getnao/nao/deploy-context/Gen Agent Trust Hub

deploy-context

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The instructions promote secure secrets management by directing users to store sensitive credentials like NAO_API_KEY in GitHub Secrets rather than hardcoding them in configuration files or code.
  • [SAFE]: The skill utilizes official vendor resources, including the nao-core CLI and getnao.io domains, for its deployment operations.
  • [SAFE]: The provided GitHub Actions workflow uses official, version-pinned actions from GitHub's verified 'actions' organization, such as actions/checkout and actions/setup-python.
  • [SAFE]: The documentation includes explicit warnings and guardrails against common security pitfalls, such as triggering deployments on untrusted pull requests from forks or printing secrets to stdout.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 08:15 PM
Security Audit — agent-trust-hub — deploy-context