iac-generation

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates within a controlled environment using specific MCP tools provided by Infracost to perform cloud cost analysis and policy enforcement.
  • [SAFE]: Security best practices are integrated into the instructions, explicitly warning the agent against committing sensitive credentials or authentication tokens to repositories.
  • [SAFE]: File system operations are scoped to necessary IaC analysis, and the skill includes directives to avoid modifying critical repository metadata (e.g., git state) or using unsafe execution methods like shell pipelines.
  • [SAFE]: No patterns of obfuscation, unauthorized remote code execution, or malicious prompt injection were detected. The logic is consistent with the stated purpose of FinOps and infrastructure management.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 01:11 AM
Security Audit — agent-trust-hub — iac-generation