skills/immamdouhaboammar/antigravity-superpowers/agency-cloud-security-architect/Gen Agent Trust Hub
agency-cloud-security-architect
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes example GitHub Action workflows that reference well-known security tools and official cloud provider actions. These are used to demonstrate best practices for CI/CD security scanning and OIDC-based deployment.
bridgecrewio/checkov-action@v12(Infrastructure-as-Code scanning)gitleaks/gitleaks-action@v2(Secret detection)aquasecurity/trivy-action@master(Container vulnerability scanning)aws-actions/configure-aws-credentials@v4(Official AWS credentials management)- [CREDENTIALS_UNSAFE]: The skill explicitly enforces security standards against hardcoded credentials. It instructs the agent to 'Never allow long-lived credentials' and mandates the use of dedicated secret managers (AWS Secrets Manager, Azure Key Vault, etc.) rather than environment variables or configuration files.
- [INDIRECT_PROMPT_INJECTION]: As a security architect persona, the skill is designed to analyze user-provided architectures and logs. While this creates an ingestion surface for untrusted data, the skill includes 'Critical Rules' and 'Architecture Principles' that act as strong system-level constraints, reducing the risk of accidental obedience to instructions embedded in analyzed content.
Audit Metadata