devops-pulumi
Pass
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides instructional content and code templates for infrastructure management using Pulumi. All external references target well-known and reputable services such as GitHub and Let's Encrypt.
- [CREDENTIALS_UNSAFE]: The skill correctly instructs the user on secure secrets management, advocating for the use of
--secretflags and cloud-based Key Management Services (KMS) for production environments. Examples use standard documentation placeholders. - [COMMAND_EXECUTION]: The skill documents the use of the
pulumiCLI and Automation API. These tools are used for their intended purpose of infrastructure automation within a DevOps context. - [EXTERNAL_DOWNLOADS]: The skill references fetching Helm charts from well-known repositories such as the official Ingress-Nginx, Jetstack (Cert-Manager), and Prometheus Community repositories. These are documented neutrally and follow standard IaC practices.
Audit Metadata