infracost-scan
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses the Infracost MCP server to analyze Infrastructure as Code (IaC) files. All operations are performed through structured tool calls (scan, inspect) provided by the vendor, minimizing the risk of arbitrary command execution.\n- [SAFE]: No evidence of malicious behavior, obfuscation, or data exfiltration to unauthorized domains was detected. The skill instructions include safety warnings regarding credential management and temporary file cleanup.\n- [SAFE]: While the skill ingests third-party IaC code, the risk of indirect prompt injection is mitigated by the structured nature of the cost reports and the absence of high-privilege capabilities such as shell execution or file-write operations within the provided toolset.
Audit Metadata