enterprise-cost-governance

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a guide for implementing enterprise cloud cost governance. It contains architectural decision trees, framework pillars, and documentation for FinOps maturity models.
  • [COMMAND_EXECUTION]: The skill includes Python code templates (e.g., IdleResourceScanner, UnitEconomics, CostAnomalyDetector) designed to interface with standard cloud APIs like AWS via the boto3 library. These snippets are localized to the described purpose of identifying idle resources and detecting cost spikes, with no evidence of malicious intent or command injection.
  • [PROMPT_INJECTION]: No patterns of prompt injection, role-play overrides, or instructions to bypass safety guidelines were detected in the skill instructions or metadata.
  • [EXTERNAL_DOWNLOADS]: The skill does not contain any instructions to download or execute remote scripts. It references official cloud provider documentation and tools (AWS, Azure, GCP) neutrally.
  • [DATA_EXFILTRATION]: No patterns of credential harvesting or exfiltration of sensitive files (like .aws/credentials) were found. The mention of cloud credentials in documentation refers to standard provider configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 09:45 AM
Security Audit — agent-trust-hub — enterprise-cost-governance