devops-pulumi

Pass

Audited by Gen Agent Trust Hub on Jun 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructional content and code templates for infrastructure management using Pulumi. All external references target well-known and reputable services such as GitHub and Let's Encrypt.
  • [CREDENTIALS_UNSAFE]: The skill correctly instructs the user on secure secrets management, advocating for the use of --secret flags and cloud-based Key Management Services (KMS) for production environments. Examples use standard documentation placeholders.
  • [COMMAND_EXECUTION]: The skill documents the use of the pulumi CLI and Automation API. These tools are used for their intended purpose of infrastructure automation within a DevOps context.
  • [EXTERNAL_DOWNLOADS]: The skill references fetching Helm charts from well-known repositories such as the official Ingress-Nginx, Jetstack (Cert-Manager), and Prometheus Community repositories. These are documented neutrally and follow standard IaC practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 29, 2026, 08:47 PM
Security Audit — agent-trust-hub — devops-pulumi