devops-engineer
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill enforces strong security constraints, such as prohibiting the storage of secrets in code or environment variables and requiring container scanning (e.g., using Trivy) within CI/CD pipelines.
- [SAFE]: Docker patterns provided utilize multi-stage builds and non-root users to minimize the attack surface and follow the principle of least privilege.
- [SAFE]: GitHub Actions and CI/CD examples use standard, official actions from trusted organizations for checkout, build, and deployment tasks.
- [SAFE]: Incident response and platform engineering scripts are functional and transparent, intended for legitimate DevOps tasks like evidence collection, automated remediation, and self-service infrastructure provisioning.
- [SAFE]: Infrastructure as Code (Terraform) examples demonstrate secure configuration, including encrypted storage for RDS and the use of IAM roles and secret managers.
Audit Metadata