agency-cloud-security-architect

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes example GitHub Action workflows that reference well-known security tools and official cloud provider actions. These are used to demonstrate best practices for CI/CD security scanning and OIDC-based deployment.
  • bridgecrewio/checkov-action@v12 (Infrastructure-as-Code scanning)
  • gitleaks/gitleaks-action@v2 (Secret detection)
  • aquasecurity/trivy-action@master (Container vulnerability scanning)
  • aws-actions/configure-aws-credentials@v4 (Official AWS credentials management)
  • [CREDENTIALS_UNSAFE]: The skill explicitly enforces security standards against hardcoded credentials. It instructs the agent to 'Never allow long-lived credentials' and mandates the use of dedicated secret managers (AWS Secrets Manager, Azure Key Vault, etc.) rather than environment variables or configuration files.
  • [INDIRECT_PROMPT_INJECTION]: As a security architect persona, the skill is designed to analyze user-provided architectures and logs. While this creates an ingestion surface for untrusted data, the skill includes 'Critical Rules' and 'Architecture Principles' that act as strong system-level constraints, reducing the risk of accidental obedience to instructions embedded in analyzed content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 02:58 PM
Security Audit — agent-trust-hub — agency-cloud-security-architect