cumulus-infra
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill includes a dedicated reference for cluster secrets (secrets.md) that establishes clear safety boundaries, explicitly instructing the agent to never display secret values and providing safe methods for metadata-based troubleshooting.
- [SAFE]: Authentication mechanisms described in the skill, such as the OIDC token exchange for registry access and the use of an external secret provider (BWS), align with secure industry standards for avoiding hardcoded or long-lived credentials.
- [SAFE]: Documented commands for cluster management, including kubectl, flux CLI, and system configuration inspection, are appropriate for the skill's stated infrastructure purpose and include specific safety contexts (e.g., context-pinning to polaris-v2).
- [SAFE]: Infrastructure hardening is treated as a priority, with documentation explicitly requiring non-root execution, read-only filesystems, and default-deny network policies for all workloads.
Audit Metadata