flexport-prod-checklist
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill encourages secure secret management by explicitly advising against storing API keys in environment files and suggesting the use of dedicated secret managers.
- [SAFE]: Instructions include a security audit step to check git history for accidentally committed credentials using grep, demonstrating a proactive security posture.
- [SAFE]: Network operations and API integrations target well-known official service domains (api.flexport.com and status.flexport.com).
- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for ingesting external data via the Flexport API for health monitoring. The risk is considered safe as the integration focuses on structured shipment data and metrics, with instructions provided to ensure sensitive information remains redacted in final reports.
Audit Metadata