codespaces

Pass

Audited by Gen Agent Trust Hub on Mar 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for utilizing legitimate management tools, specifically the gh CLI, to interact with cloud environments. This includes shell access via gh codespace ssh and the configuration of lifecycle scripts such as postCreateCommand within devcontainer environments. These are standard operations for the described workflow.
  • [EXTERNAL_DOWNLOADS]: References official tools and images from trusted providers, including the GitHub CLI website (cli.github.com), Microsoft Container Registry (mcr.microsoft.com), and GitHub Container Registry (ghcr.io). These sources are recognized as safe and are documented neutrally.
  • [CREDENTIALS_UNSAFE]: Includes specific instructions on how to securely handle credentials using gh secret set, demonstrating best practices for secrets management within the GitHub ecosystem and avoiding hardcoded secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 15, 2026, 11:08 AM
Security Audit — agent-trust-hub — codespaces